Joker_
Fun Poster
- Messages
- 103
- Joined
- Apr 21, 2014
- Messages
- 103
- Reaction score
- 0
- Points
- 10
Harap maklum,dari hasil 'hunting',website-website yang tersenarai kat bawah ni terdedah untuk di exploit.
Aim : Online shop that selling Electronic Product such as E-Book,Sofware and Membership using Paypal.
Vulnerability Found : Paypal Direct Payment
Keyword : "return to merchant","back to merchant","serta merta","gain access immediately"
Vulnerability Case : The attacker can get the product or membership without paying full price.
List site :
http://www.rahsiapenulis.com
http://www.perolehankerajaan.com
http://www.rahsiarezeki.com
http://rahsiamagnetduit.com
http://rahsiakambing.com
http://www.sistemsaham.com
http://www.rahsiarumahlelong.com
http://www.rahsiataobao.com
http://www.kitforex.com
http://www.panduan-asas-forex.com
http://www.duitfiverr.com
http://www.rajaadsense.com
http://www.maskahwin.com
Macammana aku nak terangkan ni erk....~X(
Mule-mule yang ni dululah :
Client = Pay = We Receive = We give download link
Ada kalangan seller tak nak upload e-product diorang kat server untuk mengelakkan buyer sebarkan link download,ataupun hacker exploit link download,so jadinya
Client = Pay = We Receive = We give our product through email
Kat atas ni penerangan antara direct buyer ngan seller.Maknenyer antara 2 manusia.Kalau si buyer tak bayar,si seller takkan kasi barang,kalau si seller letak harga RM60,si buyer kene bayar RM60 baru dapat barang.
Sama jugak kes kalau gune Paypal direct payment :
Client = Pay = Paypal Receive = Client automatically get download link/email respons
TETAPI,yang ni susah nak ku terangkan...~X(
Aku sebagai "Client".
Si seller ni pulak buat autopilot,means if i make a payment to their paypal account,after the payment i will get the download link,information,email,etc.
Clue = after the payment,bermaksud buat saje payment,kite terus akan dapat download link,information ataupun email mengenai e-product tersebut.
Logiknye walau bayar 0.01 pon dah dianggap payment betul tak ?
)
)
Before Server A send to Server B,test out either Server A have checksum,if no checksum,edit the POST before the parameter reach at Server B.
Satu contoh vulnerability,website jual sofware gune payment success = get product
Total price = 129.50
Pay 0.01 (Like i said,0.01 sudah dianggap payment betul tak?)
Instant download link + Serial Number~X(
Sape-sape yang nak copy serial number tu dah terlambat...Aku dah notify owner website.Serial tu dah kene cancel.
)
Checksum check
Untuk owner website,agak susah untuk aku terangkan disebabkan aku tak cukup pengetahuan lagi.Aku sarankan,yang nak gune paypal ni,jangan terus bagi direct download,buat pengesahan dulu.Manual lagi selamat.
paid
Ade sape2 nak tambah website untuk tujuan vulnerability tester boleh post kat sini...
Aim : Online shop that selling Electronic Product such as E-Book,Sofware and Membership using Paypal.
Vulnerability Found : Paypal Direct Payment
Keyword : "return to merchant","back to merchant","serta merta","gain access immediately"
Vulnerability Case : The attacker can get the product or membership without paying full price.
List site :
http://www.rahsiapenulis.com
http://www.perolehankerajaan.com
http://www.rahsiarezeki.com
http://rahsiamagnetduit.com
http://rahsiakambing.com
http://www.sistemsaham.com
http://www.rahsiarumahlelong.com
http://www.rahsiataobao.com
http://www.kitforex.com
http://www.panduan-asas-forex.com
http://www.duitfiverr.com
http://www.rajaadsense.com
http://www.maskahwin.com
Macammana aku nak terangkan ni erk....~X(
Mule-mule yang ni dululah :
Client = Pay = We Receive = We give download link
Ada kalangan seller tak nak upload e-product diorang kat server untuk mengelakkan buyer sebarkan link download,ataupun hacker exploit link download,so jadinya
Client = Pay = We Receive = We give our product through email
Kat atas ni penerangan antara direct buyer ngan seller.Maknenyer antara 2 manusia.Kalau si buyer tak bayar,si seller takkan kasi barang,kalau si seller letak harga RM60,si buyer kene bayar RM60 baru dapat barang.
Sama jugak kes kalau gune Paypal direct payment :
Client = Pay = Paypal Receive = Client automatically get download link/email respons
TETAPI,yang ni susah nak ku terangkan...~X(
Aku sebagai "Client".
Si seller ni pulak buat autopilot,means if i make a payment to their paypal account,after the payment i will get the download link,information,email,etc.
Clue = after the payment,bermaksud buat saje payment,kite terus akan dapat download link,information ataupun email mengenai e-product tersebut.
Logiknye walau bayar 0.01 pon dah dianggap payment betul tak ?
Before Server A send to Server B,test out either Server A have checksum,if no checksum,edit the POST before the parameter reach at Server B.
Satu contoh vulnerability,website jual sofware gune payment success = get product
Total price = 129.50
Pay 0.01 (Like i said,0.01 sudah dianggap payment betul tak?)
Instant download link + Serial Number~X(
Sape-sape yang nak copy serial number tu dah terlambat...Aku dah notify owner website.Serial tu dah kene cancel.
Checksum check
Untuk owner website,agak susah untuk aku terangkan disebabkan aku tak cukup pengetahuan lagi.Aku sarankan,yang nak gune paypal ni,jangan terus bagi direct download,buat pengesahan dulu.Manual lagi selamat.
Ade sape2 nak tambah website untuk tujuan vulnerability tester boleh post kat sini...
Last edited:
