Web Hack List

Collected research

Detecting Logic Vulnerabilities in E-Commerce Applications

A static analysis that combines symbolic execution with taint tracking to find logic flaws in PHP e-commerce checkout code, using the invariant that a secure checkout preserves the integrity and authenticity of order ID, order total, merchant ID and currency. Violations let a shopper pay the wrong amount, pay a different merchant, or take goods without paying.

Record

Researcher
Fangqi Sun, Liang Xu and Zhendong Su
Published by
NDSS Symposium
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Fangqi Sun, Liang Xu and Zhendong Su, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .