USENIX Security2022Top-tier venue
Playing Without Paying: Detecting Vulnerable Payment Verification in Native Binaries of Unity Mobile Games
Chaoshun Zuo, Zhiqiang Lin
Abstract
Modern mobile games often contain in-app purchasing (IAP) for players to purchase digital items such as virtual currency, equipment, or extra moves. In theory, IAP should have been implemented securely; but in practice, we have found that many game developers have failed to do so, particularly by misplacing the trust of payment verification, e.g., by either locally verifying the payment transactions or without using any verification at all, leading to playing without paying vulnerabilities. This paper presents PAYMENTSCOPE, a static binary analysis tool to automatically identify vulnerable IAP implementations in mobile games. Through modeling of its IAP protocols with the SDK provided APIs using a paymentaware data flow analysis, PAYMENTSCOPE directly pinpoints untrusted payment verification vulnerabilities in game native binaries. We have implemented PAYMENTSCOPE on top of binary analysis framework Ghidra, and tested with 39,121 Unity (the most popular game engine) mobile games, with which PAYMENTSCOPE has identified 8,954 (22.89%) vulnerable games. Among them, 8,233 games do not verify the validity of payment transactions and 721 games simply verify the transactions locally. We have disclosed the identified vulnerabilities to developers of vulnerable games, and many of them have acknowledged our findings.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ff42caf7-4bc2-4341-b778-b249ec5c9ac9Cited by top-tier papers6
- An Empirical Study on Oculus Virtual Reality Applications: Security and Privacy PerspectivesHanyang Guo, Hong-Ning Dai, Xiapu Luo, Zibin Zheng et al.ICSE 2024 · 17 citations
- A Peek into the Metaverse: Detecting 3D Model Clones in Mobile GamesChaoshun Zuo, Chao Wang, Zhiqiang LinUSENIX Security 2023
- In Wallet We Trust: Bypassing the Digital Wallets Payment Security for Free ShoppingRaja Hasnain Anwar, Syed Rafiul Hussain, Muhammad Taqi RazaUSENIX Security 2024
- AUTOVR: Automated UI Exploration for Detecting Sensitive Data Flow Exposures in Virtual Reality AppsJohn Y. Kim, Chaoshun Zuo, Yanjie Zhao, Zhiqiang LinUSENIX Security 2025
- Egg Hunt in Tesla Infotainment: A First Look at Reverse Engineering of Qt BinariesHaohuang Wen, Zhiqiang LinUSENIX Security 2023
Builds on9
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens et al.S&P 2016 · 1,085 citations
- Why Does Your Data Leak? Uncovering the Data Leakage in Cloud from Mobile AppsChaoshun Zuo, Zhiqiang Lin, Yinqian ZhangS&P 2019 · 123 citations
- You are a Game Bot!: Uncovering Game Bots in MMORPGs via Self-similarity in the WildEunjo Lee, Jiyoung Woo, Hyoungshick Kim, Aziz Mohaisen et al.NDSS 2016 · 54 citations
- FirmXRay: Detecting Bluetooth Link Layer Vulnerabilities From Bare-Metal FirmwareHaohuang Wen, Zhiqiang Lin, Yinqian ZhangCCS 2020 · 47 citations
- SelectiveTaint: Efficient Data Flow Tracking With Static Binary RewritingSanchuan Chen, Zhiqiang Lin, Yinqian ZhangUSENIX Security 2021 · 45 citations
Related papers
- AUTHSCOPE: Towards Automatic Discovery of Vulnerable Authorizations in Online ServicesChaoshun Zuo, Qingchuan Zhao, Zhiqiang LinCCS 2017 · 59 citations
- Uncovering and Exploiting Hidden APIs in Mobile Super AppsChao Wang, Yue Zhang, Zhiqiang LinCCS 2023 · 11 citations
- Automatic Uncovering of Hidden Behaviors From Input Validation in Mobile AppsQingchuan Zhao, Chaoshun Zuo, Brendan Dolan-Gavitt, Giancarlo Pellegrino et al.S&P 2020 · 33 citations
- Broken Fingers: On the Usage of the Fingerprint API in AndroidAntonio Bianchi, Yanick Fratantonio, Aravind Machiry, Christopher Kruegel et al.NDSS 2018 · 33 citations
- Detecting and Measuring Misconfigured Manifests in Android AppsYuqing Yang, Mohamed Elsabagh, Chaoshun Zuo, Ryan Johnson et al.CCS 2022 · 11 citations
