My First Medium‑Severity Vulnerability: Exploiting Leaked Test Accounts in an EduCN Portal

The author describes discovering a medium‑severity information‑leak vulnerability in an educational portal by using a Google dork to locate a file exposing three default test accounts, then logging in with the admin credentials (password 123456) after other attack attempts failed.

Black & White Path
Black & White Path
Black & White Path
My First Medium‑Severity Vulnerability: Exploiting Leaked Test Accounts in an EduCN Portal

The article reports a medium‑severity vulnerability discovered in January on an educational website.

The author employed the Google dork

site:edu.cn intext:"测试账号" "试用账号" filetype:xls|pdf|doc|docx

to search for files that contain test‑account information. The search returned a document listing three test accounts—student, teacher, and admin—each using the password 123456.

图片
图片

The author first attempted common penetration‑testing techniques such as brute‑force password guessing, using a universal SQL password, and exploiting password‑reset logic flaws, but none succeeded in gaining access.

Using the leaked credentials, the author logged in with the highest‑privilege admin (教务) account. The login succeeded, granting full administrative rights, as shown in the following screenshots.

图片
图片
图片
图片

The author concludes that default test accounts with weak passwords constitute an information‑leak vulnerability of medium severity, underscoring the need for educational institutions to remove or secure such accounts to prevent unauthorized access.

Original Source

Signed-in readers can open the original source through BestHub's protected redirect.

Sign in to view source
Republication Notice

This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactadmin@besthub.devand we will review it promptly.

vulnerabilityinformation leakageGoogle dorkeducation domainmedium severitytest accounts
Black & White Path
Written by

Black & White Path

We are the beacon of the cyber world, a stepping stone on the road to security.

0 followers
Reader feedback

How this landed with the community

Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.