iNTHU App Reverse Engineering #441
Replies: 1 comment
-
It seems like The resulting code ends up at osa.nthu.edu.tw, where the HTML contains
We can see that it is supposed to scoped to web only, but Im guessing someone fucked up, so we can use the mobile API Of course being National Tsing Hua Uni, we can't be bothered to follow conventions, so the JWT is another custom string
Taking this token as the Header in Authorization, with DeviceID, you can then access all of iNTHU. |
Beta Was this translation helpful? Give feedback.
-
https://osa.nthu.edu.tw/app/app_privacypolicy.aspx?lang=en
https://oauth.ccxp.nthu.edu.tw/v1.1/authorize.php?client_id=saweb&response_type=code&redirect_uri=https%3A%2F%2Fosa.nthu.edu.tw%2Fapi%2Fcallback.aspx&scope=uuid+inschool+userid+name+email&ui_locales=en-US&state=mobile,en
Attendance: https://osa.nthu.edu.tw/app/acsystem.aspx
Home Page: https://osa.nthu.edu.tw/App/Default.aspx?lang=cht
Door QR code: https://osa.nthu.edu.tw/app/pkmrec.aspx
Beta Was this translation helpful? Give feedback.
All reactions