All Your Shops Are Belong to Us: Security Weaknesses in E-commerce Platforms

Rohan Pagey, Mohammad Mannan, Amr M. Youssef
{"title":"All Your Shops Are Belong to Us: Security Weaknesses in E-commerce Platforms","authors":"Rohan Pagey, Mohammad Mannan, Amr M. Youssef","doi":"10.1145/3543507.3583319","DOIUrl":null,"url":null,"abstract":"Software as a Service (SaaS) e-commerce platforms for merchants allow individual business owners to set up their online stores almost instantly. Prior work has shown that the checkout flows and payment integration of some e-commerce applications are vulnerable to logic bugs with serious financial consequences, e.g., allowing “shopping for free”. Apart from checkout and payment integration, vulnerabilities in other e-commerce operations have remained largely unexplored, even though they can have far more serious consequences, e.g., enabling “store takeover”. In this work, we design and implement a security evaluation framework to uncover security vulnerabilities in e-commerce operations beyond checkout/payment integration. We use this framework to analyze 32 representative e-commerce platforms, including web services of 24 commercial SaaS platforms and 15 associated Android apps, and 8 open source platforms; these platforms host over 10 million stores as approximated through Google dorks. We uncover several new vulnerabilities with serious consequences, e.g., allowing an attacker to take over all stores under a platform, and listing illegal products at a victim’s store—in addition to “shopping for free” bugs, without exploiting the checkout/payment process. We found 12 platforms vulnerable to store takeover (affecting 41000+ stores) and 6 platforms vulnerable to shopping for free (affecting 19000+ stores, approximated via Google dorks on Oct. 8, 2022). We have responsibly disclosed the vulnerabilities to all affected parties, and requested four CVEs (three assigned, and one is pending review).","PeriodicalId":296351,"journal":{"name":"Proceedings of the ACM Web Conference 2023","volume":"39 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-04-30","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the ACM Web Conference 2023","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3543507.3583319","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

Abstract

Software as a Service (SaaS) e-commerce platforms for merchants allow individual business owners to set up their online stores almost instantly. Prior work has shown that the checkout flows and payment integration of some e-commerce applications are vulnerable to logic bugs with serious financial consequences, e.g., allowing “shopping for free”. Apart from checkout and payment integration, vulnerabilities in other e-commerce operations have remained largely unexplored, even though they can have far more serious consequences, e.g., enabling “store takeover”. In this work, we design and implement a security evaluation framework to uncover security vulnerabilities in e-commerce operations beyond checkout/payment integration. We use this framework to analyze 32 representative e-commerce platforms, including web services of 24 commercial SaaS platforms and 15 associated Android apps, and 8 open source platforms; these platforms host over 10 million stores as approximated through Google dorks. We uncover several new vulnerabilities with serious consequences, e.g., allowing an attacker to take over all stores under a platform, and listing illegal products at a victim’s store—in addition to “shopping for free” bugs, without exploiting the checkout/payment process. We found 12 platforms vulnerable to store takeover (affecting 41000+ stores) and 6 platforms vulnerable to shopping for free (affecting 19000+ stores, approximated via Google dorks on Oct. 8, 2022). We have responsibly disclosed the vulnerabilities to all affected parties, and requested four CVEs (three assigned, and one is pending review).
你所有的商店都属于我们:电子商务平台的安全弱点
面向商家的软件即服务(SaaS)电子商务平台允许个体企业主几乎立即建立自己的在线商店。先前的工作表明,一些电子商务应用程序的结帐流程和支付集成容易受到逻辑错误的影响,从而导致严重的财务后果,例如,允许“免费购物”。除了结帐和支付集成之外,其他电子商务业务的漏洞在很大程度上仍未被探索,尽管它们可能会产生更严重的后果,例如导致“商店接管”。在这项工作中,我们设计并实现了一个安全评估框架,以发现电子商务操作中结帐/支付集成之外的安全漏洞。我们用这个框架分析了32个有代表性的电子商务平台,包括24个商业SaaS平台的web服务和15个关联的Android应用,以及8个开源平台;根据Google的统计,这些平台拥有超过1000万家商店。我们发现了几个具有严重后果的新漏洞,例如,允许攻击者接管平台下的所有商店,并在受害者的商店中列出非法产品-除了“免费购物”漏洞之外,还没有利用结帐/支付过程。我们发现12个平台容易受到商店接管的影响(影响41000多家商店),6个平台容易受到免费购物的影响(影响19000多家商店,根据谷歌呆子在2022年10月8日的估计)。我们负责任地向所有受影响方披露了漏洞,并请求了四个cve(三个已分配,一个正在审查中)。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信