Auditing Payment Callback And Amount Integrity

Audit payment provider callbacks and settlement notifications for the trust that lets an attacker forge or alter a payment result: a callback whose signature is not verified so a spoofed success is accepted, an amount or currency taken from the callback or client rather than reconciled against the order the server created, a success notification not bound to a specific order so it can be replayed onto another order, and a settled status trusted without confirming it out of band with the provider. Covers redirect returns, server-to-server webhooks, and status polls where a payment processor tells the application a charge succeeded. Use when the application learns a payment result from an external processor and that message gates fulfillment. The forged or altered payment notification is the source, the order marked paid and fulfilled is the sink, and the unverified signature, unreconciled amount, or unbound order reference is the bug.

UnboundCompute 41fee23 10.2 KB Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/auditing-payment-callback-and-amount-integrity commit 41fee238fa

Frequently asked questions

npx skillmds@latest add unboundcompute/auditing-payment-callback-and-amount-integrity