Rithwik Jayasimha (@thel3l) on X

1 min read Original article ↗

Post

Post

  • user avatar

    Last year, a friend was planning a trip to an amusement park for her bday. Site design is often a good heuristic for security and the design wasn't inspiring confidence—so I went poking. A fun story of finding a payment bypass in PayU India and the subsequent disclosure arc:

    amusment park clearly not amused with my kind, and have obviously had folks bother them before haha

    user avatar

    In the coming day or two, I'll be sharing the full details on how it was possible to bypass PayU India's hosted checkout flow and get free stuff from any merchant bonus: failed managed disclosure programs, my credit card being abused, and

    @IndianCERT

    being awesome!

  • user avatar

    I don’t get it, from my understanding it’s the park dev’s fault for letting the client make the request to the payment provider. Usually the server would make the request.

  • user avatar

  • user avatar

    "In the coming day or two, I'll be sharing the full details"😅 Ahem.

    user avatar

    In the coming day or two, I'll be sharing the full details on how it was possible to bypass PayU India's hosted checkout flow and get free stuff from any merchant bonus: failed managed disclosure programs, my credit card being abused, and

    @IndianCERT

    being awesome!