instavm/security-skills

mitm-find-callback

Find payment callback and webhook vulnerabilities. Use when user asks about payment security, callback tampering, hash validation, or transaction manipulation.

First seen Mar 23, 2026

Installation

$ npx skills add instavm/security-skills --skill mitm-find-callback

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from instavm/security-skills · top by installs.

npx skills add instavm/security-skills

Browse all from instavm/security-skills

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 84
Default branch main
Open issues 0
Status Active

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 1,975 B
  • docs SUMMARY.md 185 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 57 installs

SKILL.md

Find Payment Callback Vulnerabilities

Analyze the mitmproxy dump (log.txt) for payment callback issues for: $ARGUMENTS

Requires: log.txt in the current directory. If it's missing, capture traffic first:
```bash
mitmdump --set flow_detail=3 2>&1 | tee log.txt
```

Vulnerability Types

1. Hash/Signature Not Validated

  • Callback accepts any hash value
  • Hash parameter present but not verified
  • Can change status without valid signature

2. Status Manipulation

  • Change status=failed to status=success
  • Modify unmappedstatus parameter
  • Tamper with transaction result

3. Amount Manipulation

  • Modify amount before callback
  • Pay less, get full order
  • Decimal manipulation

4. Signature Collision

  • Same signature works for payment and refund
  • Parameter reordering gives same hash
  • Missing fields in signature calculation

5. Checksum Generation Exposed

  • API returns checksum even on error
  • Can generate arbitrary checksums
  • Checksum algorithm is weak (MD5/SHA1 without salt)

Testing Approach

# Test callback with modified status
curl -X POST "https://merchant.com/payment/callback" \
  -d "txnid=12345&status=success&hash=original_hash"

# Test with invalid hash
curl -X POST "https://merchant.com/payment/callback" \
  -d "txnid=12345&status=success&hash=aaaa"

Red Flags in Traffic

  • Callback URLs with all params in request
  • Hash visible in client-side code
  • Salt/secret in JavaScript
  • Error responses containing valid checksums

Output Format

For each finding:

  • Callback URL: Vulnerable endpoint
  • Issue: What can be manipulated
  • Parameters: Affected fields
  • Test: How to exploit
  • Impact: Free orders, refunds, etc.
  • Fix: Proper server-side validation