本文转自夏日2791的知乎
很可能在这(假的)300s内,它会验证你的QQ是否有安全令牌,有的话,它登录QQ需要本人用手机号验证,会叫你发送短信通过它的验证。然后QQ成功被盗取,再次发送同样的腾讯文档出去。
我没有得到下一步的php,很可能是因为我填写的QQ关闭了安全令牌。而且我填写的身份信息无一例外是随机生成的。
关闭安全令牌的原因我是想让它登录我的新注册的QQ,我不可能让它知道我的绑定手机号。
经过上面的行为,网站获取了你的QQ号,密码,姓名,绑定手机,身份证,就读大学,父母电话。这些信息很有可能被用来盗取QQ号,诈骗你的父母。
其实这些网站它的域名都很奇怪,填写重要信息的时候要多加注意网站的域名,官方的网站域名都不会乱七八糟。不确定的话,可以去看看网站是否有备案。
这个网站它没有getIndex的文件,ajax.php也几乎什么都没有。我无法看出网站的数据发送到了哪里。
很可能这个网站获取的数据是存到了本地的云服务器。用nmap扫描后发现有3306端口。mysql无法匿名登陆,得到没有mysqld:ALL的错误类型。
碰到这种垃圾网站请获取域名请在中央网信办举报中心处举报。
コメント
There are a lot of ads like normal comments below this post. I deleted the part of their ad, lol
Right here is the right web site for anyone who really wants to find out
about this topic. You know a whole lot its almost hard to argue with you (not
that I really will need to…HaHa). You certainly put a new spin on a subject that's
been written about for years. Wonderful stuff, just excellent!
Do you mind if I quote a couple of your posts as long as I provide credit and
sources back to your webpage? My blog is in the exact same area of interest as yours and my visitors would certainly benefit from a lot of the information you present here.
Please let me know if this ok with you. Thanks a lot!
whoah this weblog is fantastic i really like reading your posts.
Stay up the great work! You realize, a lot of individuals are looking round for this info, you could aid them greatly.
教学贴,感谢老司机