Messy States of Wiring: Vulnerabilities in Emerging Personal Payment Systems

Messy States of Wiring: Vulnerabilities in Emerging Personal Payment Systems
复制标题

DOI:
--
复制
发表时间:
2021
期刊:
--
影响因子:
--
通讯作者:
Jiadong Lou;Xu Yuan;Ning Zhang
Jiadong Lou;Xu Yuan;Ning Zhang
中科院分区:
其他
文献类型:
--
作者:
Jiadong Lou;Xu Yuan;Ning Zhang

文献摘要

被引文献

相似文献

本文介绍了我们对一种新兴支付服务范式的研究,该范式允许个体商户利用第三方平台上的个人转账服务来支持商业交易。这是通过利用一个额外的订单管理系统,统称为个人支付系统(PPS)实现的。为了更好地了解这些新兴系统,我们对35个PPS进行了系统研究,涵盖超过11740个商户客户,支持超过2000万客户。通过检查文档、可用的源代码和演示,我们提取了一个通用的PPS抽象模型,并在现有的个人支付协议设计和系统实现中发现了7类漏洞。令人担忧的是,所有正在研究的PPS都至少有一个漏洞。为了进一步剖析这些潜在的弱点,我们提出了相应的攻击方法来利用所发现的漏洞。为了验证我们提出的攻击,我们进行了四次成功的真实攻击,以说明严重的后果。我们负责任地披露了新发现的漏洞,并在我们的报告后修补了一些漏洞。
This paper presents our study on an emerging paradigm of payment service that allows individual merchants to leverage the personal transfer service in third-party platforms to support commercial transactions. This is made possible by leveraging an additional order management system, collectively named Personal Payment System (PPS) . To gain a better understanding of these emerging systems, we conducted a systematic study on 35 PPS s covering over 11740 mer-chant clients supporting more than 20 million customers. By examining the documentation, available source codes, and demos, we extracted a common abstracted model for PPS and discovered seven categories of vulnerabilities in the existing personal payment protocol design and system implementation. It is alarming that all PPS s under study have at least one vulnerability. To further dissect these potential weaknesses, we present the corresponding attack methods to exploit the discovered vulnerabilities. To validate our proposed attacks, we conducted four successful real attacks to illustrate the severe consequences. We have responsibly disclosed the newly discovered vulnerabilities, with some patched after our reporting.