USENIX Security2021Top-tier venue
Messy States of Wiring: Vulnerabilities in Emerging Personal Payment Systems
Jiadong Lou, Xu Yuan, Ning Zhang
Abstract
This paper presents our study on an emerging paradigm of payment service that allows individual merchants to leverage the personal transfer service in third-party platforms to support commercial transactions. This is made possible by leveraging an additional order management system, collectively named Personal Payment System (PPS). To gain a better understanding of these emerging systems, we conducted a systematic study on 35 PPSs covering over 11740 merchant clients supporting more than 20 million customers. By examining the documentation, available source codes, and demos, we extracted a common abstracted model for PPS and discovered seven categories of vulnerabilities in the existing personal payment protocol design and system implementation. It is alarming that all PPSs under study have at least one vulnerability. To further dissect these potential weaknesses, we present the corresponding attack methods to exploit the discovered vulnerabilities. To validate our proposed attacks, we conducted four successful real attacks to illustrate the severe consequences. We have responsibly disclosed the newly discovered vulnerabilities, with some patched after our reporting.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9d1b5447-dfd8-4e32-894c-9a08438465f5Cited by top-tier papers5
- All Your Shops Are Belong to Us: Security Weaknesses in E-commerce PlatformsRohan Pagey, Mohammad Mannan, Amr M. YoussefWWW 2023 · 10 citations
- Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless PaymentsRaja Hasnain Anwar, Gerard DeCunha, Muhammad Taqi RazaUSENIX Security 2026
- When HTTP 402 Meets the Blockchain: Risks on Emerging x402 PaymentsQinying Wang, Yong Yang, Yuan Chen, Shouling Ji et al.USENIX Security 2026
- In Wallet We Trust: Bypassing the Digital Wallets Payment Security for Free ShoppingRaja Hasnain Anwar, Syed Rafiul Hussain, Muhammad Taqi RazaUSENIX Security 2024
- When Authorization Loses Its Meaning: Breaking and Fixing Third-Party Online PaymentsYongkang Xiao, Jing Chen, Min Shi, Kun He et al.USENIX Security 2026
Builds on4
- Show Me the Money! Finding Flawed Implementations of Third-party In-app Payment in Android AppsWenbo Yang, Yuanyuan Zhang, Juanru Li, Hui Liu et al.NDSS 2017 · 40 citations
- Attack Patterns for Black-Box Security Testing of Multi-Party Web ApplicationsAvinash Sudhodanan, Alessandro Armando, Roberto Carbone, Luca CompagnaNDSS 2016 · 36 citations
- Devils in the Guidance: Predicting Logic Vulnerabilities in Payment Syndication Services through Automated Documentation AnalysisYi Chen, Luyi Xing, Yue Qin, Xiaojing Liao et al.USENIX Security 2019 · 33 citations
- The Cards Aren't Alright: Detecting Counterfeit Gift Cards Using Encoding JitterNolen Scaife, Christian Peeters, Camilo Velez, Hanqing Zhao et al.S&P 2018 · 11 citations
Related papers
- A Formal Security Analysis of the W3C Web Payment APIs: Attacks and VerificationQuoc Huy Do, Pedram Hosseyni, Ralf Küsters, Guido Schmitz et al.S&P 2022 · 6 citations
- Security Analysis of Unified Payments Interface and Payment Apps in IndiaRenuka Kumar, Sreesh Kishore, Hao Lu, Atul PrakashUSENIX Security 2020
- "Please don't send that bot anything": A Mixed-methods Study of Personal Impersonation Attacks Targeting Digital Payments on Social MediaHoang Dai Nguyen, Sumit Dhungana, Madhulika Itha, Phani VadrevuUSENIX Security 2025
- On Privacy Weaknesses and Vulnerabilities in Software SystemsPattaraporn Sangaroonsilp, Hoa Khanh Dam, Aditya GhoseICSE 2023 · 4 citations
- "Only as Strong as the Weakest Link": On the Security of Brokered Single Sign-On on the WebTommaso Innocenti, Louis Jannett, Christian Mainka, Vladislav Mladenov et al.S&P 2025
