All Your Shops Are Belong to Us: Security Weaknesses in E-commerce Platforms
Rohan Pagey, Mohammad Mannan, Amr M. Youssef
Abstract
Software as a Service (SaaS) e-commerce platforms for merchants allow individual business owners to set up their online stores almost instantly. Prior work has shown that the checkout flows and payment integration of some e-commerce applications are vulnerable to logic bugs with serious financial consequences, e.g., allowing "shopping for free". Apart from checkout and payment integration, vulnerabilities in other e-commerce operations have remained largely unexplored, even though they can have far more serious consequences, e.g., enabling "store takeover". In this work, we design and implement a security evaluation framework to uncover security vulnerabilities in e-commerce operations beyond checkout/payment integration. We use this framework to analyze 32 representative e-commerce platforms, including web services of 24 commercial SaaS platforms and 15 associated Android apps, and 8 open source platforms; these platforms host over 10 million stores as approximated through Google dorks. We uncover several new vulnerabilities with serious consequences, e.g., allowing an attacker to take over all stores under a platform, and listing illegal products at a victim's store-in addition to "shopping for free" bugs, without exploiting the checkout/payment process. We found 12 platforms vulnerable to store takeover (affecting 41000+ stores) and 6 platforms vulnerable to shopping for free (affecting 19000+ stores, approximated via Google dorks on Oct. 8, 2022). We have responsibly disclosed the vulnerabilities to all affected parties, and requested four CVEs (three assigned, and one is pending review). CCS CONCEPTS • Security and privacy → Web application security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on6
- The Cookie Hunter: Automated Black-box Auditing for Web Authentication and Authorization FlawsKostas Drakonakis, Sotiris Ioannidis, Jason PolakisCCS 2020 · 56 citations
- Show Me the Money! Finding Flawed Implementations of Third-party In-app Payment in Android AppsWenbo Yang, Yuanyuan Zhang, Juanru Li, Hui Liu et al.NDSS 2017 · 40 citations
- Attack Patterns for Black-Box Security Testing of Multi-Party Web ApplicationsAvinash Sudhodanan, Alessandro Armando, Roberto Carbone, Luca CompagnaNDSS 2016 · 36 citations
- Towards Automated Auditing for Account and Session Management Flaws in Single Sign-On DeploymentsMohammad Ghasemisharif, Chris Kanich, Jason PolakisS&P 2022 · 25 citations
- Having Your Cake and Eating It: An Analysis of Concession-Abuse-as-a-ServiceZhibo Sun, Adam Oest, Penghui Zhang, Carlos E. Rubio-Medrano et al.USENIX Security 2021 · 16 citations
Related papers
- Messy States of Wiring: Vulnerabilities in Emerging Personal Payment SystemsJiadong Lou, Xu Yuan, Ning ZhangUSENIX Security 2021 · 4 citations
- A Formal Security Analysis of the W3C Web Payment APIs: Attacks and VerificationQuoc Huy Do, Pedram Hosseyni, Ralf Küsters, Guido Schmitz et al.S&P 2022 · 6 citations
- Experimental Security Analysis of Sensitive Data Access by Browser ExtensionsAsmit Nayak, Rishabh Khandelwal, Earlence Fernandes, Kassem FawazWWW 2024 · 12 citations
- Deemon: Detecting CSRF with Dynamic Analysis and Property GraphsGiancarlo Pellegrino, Martin Johns, Simon Koch, Michael Backes et al.CCS 2017 · 74 citations
- SCAMMAGNIFIER: Piercing the Veil of Fraudulent Shopping Website CampaignsMarzieh Bitaab, Alireza Karimi, Zhuoer Lyu, Adam Oest et al.NDSS 2025
