HomeRapidalert Developers identified a weakness in the Paysafe API!

[EXCLUSIVE] Developers identified a vulnerability in the Paysafe API!

paysafecard1

Greek developers managed, according to information shared with the editorial team of SecNews, to identify a weakness in the management of the Paysafe API. Specifically, the developers of SoccerBot (software that helps bettors to search very quickly for possible football match results according to its creators) identified the weakness in the Paysafe API.

Soccerbot-Team developers Kondor and Zerocode or +Serializer+ , according to what Zerocode says in his communication with the editor of SecNews, created the Proof of Concept of the vulnerability. As they clarify, the vulnerability is not in the API but in the exploitation of an unprotected point in Paysafe that allows the creation of code that functions as an “authorized” API.

The discovery of the vulnerability was a random event. The application initially supported only Paypal, so due to increased demand from Soccerbot users, the developers considered it important to support Paysafe . During the process of the necessary implementation, the developers Kondor and Zerocode or +Serializer+ identified the vulnerability and IMMEDIATELY informed the company as they should.

soccerbot2

For this purpose, they created a Python script (shown in the relevant video that we publish below) called paysafe_cracked_api.py. The proof-of-concept code was created on the local server, since the goal of the developers was not to make a profit but to inform the company about the vulnerability.

soccerbot1

During the communication it makes, the Script checks if there are any transaction requests. If there are, it collects the data and connects to an unprotected part of Paysafe (automatically as Zerocode reports) to deposit the amount into an account corresponding to a bank card.

Watch the full video of the developers' process as they made it public:

https://www.youtube.com/watch?v=3AZT5iLNRfA

When asked by the SecNews editor about the company's reaction, the developers told us that they tried to contact them earlier, but the company, and they showed no interest in analyzing the specific problem identified by the developers and providing a solution. According to the developers, the fix is ​​very easy.

paysafe2

It is possible for a malicious user to use this methodology for payments on websites of their interest without any authorization from Paysafe. In combination with the use of a Botnet with the necessary configuration of the python script, it would be possible to test paysafe cards with one test per second.

In fact, they express their concern that such a large company made such a significant mistake, which could lead to losses, according to the claims of the developers/researchers.

SecNews was unable to evaluate the finding, as we do not have access to the source code of the python script created by the developers.

[alert]
However, we believe that the company should contact the developers IMMEDIATELY to be accurately informed and to proceed with the relevant evaluation, since it itself knows its systems and how they can be affected by the use of the unauthorized API.[/alert]

A typical example of the developers' intentions, as Zerocode specifically states, is:

[blockquote]We will continue to hold our morals high and use our knowledge for good whether we are rewarded for it or not..

Best regards, Soccerbot-Team[/blockquote]

 SecNews thanks the developers of Soccer-bot for the timely and accurate information

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS