WeChat Pay official urgently pushes tips on repairing XXE vulnerabilities, attached

2018-08-02 17:54 Category: Technical school View( )
WeChat Pay official urgently pushes tips on repairing XXE vulnerabilities, attached

Yesterday, a piece of news about WeChat Pay’s 0 yuan purchase went viral in the development circle. The so-called 0 yuan purchase is not a lottery for users, but a malicious attacker using a loophole to achieve 0 yuan payment.

The normal basic payment process is as follows: the user initiates payment -> calls up WeChat payment -> payment is successful -> the WeChat payment server sends a successful notification to the application (such as a mall) server -> the application server parses the notification sent by WeChat payment -> the parsed information performs necessary comparison and confirmation and updates the order to paid status.

However, this vulnerability is a malicious use of the parsing process, which can cause problems such as reading any file, intranet detection, and command execution.

Scan the QR code to communicate with the project manager

We are waiting for your voice 24 hours a day on WeChat

Answer questions in this article/Technical consultation/Operation consultation/Technical advice/Internet communication

We solemnly declare: Any unit or individual outside the XX network is not allowed to use this case as a demonstration of work success!
Exchange rate world
Know the exchange rate
Check exchange rate
Find a dictionary
You Dictionary
ITBar
51Exchange rate network
Niuzhan.com
Teaitao
Movie Nest
Check report
Baicao Garden
Pleasant to live
Exchange rate world
Know the exchange rate
Check exchange rate
Find a dictionary
You Dictionary
ITBar
51Exchange rate network
Niuzhan.com
Teaitao
Movie Nest
Check report
Baicao Garden
Pleasant to live