Anudeep Vysyaraju
4 min readNov 6, 2023

--

How I sent multiple payment requests on PhonePe, Paytm, and Google Pay ๐Ÿค‘๐Ÿ’ฐ

Good day ppl! This is Anudeep Vysyaraju, with a new write-up on how I sent multiple payment requests to users on their PhonePe, Paytm, and Google Pay.

Also, Iโ€™m coming up with more interesting writeups, and letโ€™s hack together!! ๐Ÿ‘จโ€๐Ÿ’ป๐Ÿง‘โ€๐Ÿ’ป

Let's get startedโ€ฆ

Razorpay

Few lines about Razorpay!!

Razorpay helps you accept online payments from customers across Desktop, Mobile web, Android & iOS. Additionally, by using Razorpay Payment Links, you can collect payments across multiple channels like SMS, Email, WhatsApp, Chatbots & Messenger.

Letโ€™s re-create the scenario!!

I just want to prank ๐Ÿ˜… my friends in a new way, So Iโ€™m thinking and searching for some alternative ways to prank them ๐Ÿ˜‚๐Ÿ˜‚ and I got an idea for Rate-Limiting vulnerability, If I use any routine things such as OTPs, etc it wonโ€™t be much interesting ๐Ÿ˜‚๐Ÿ˜… and they just ignore those messages.

So I found an alternative way for Rate-Limiting just to prank my friends ๐Ÿ˜‚

This is how my hunt started on this website for vulnerabilities๐Ÿ˜ˆ๐Ÿ˜ˆ

Letโ€™s move into the hack!!!!

I started searching ๐Ÿ” for a website that has a Rate-Limiting vulnerability and found nothing. After some time I got an idea and just wanted to check whether it's possible or not on a website, So quickly I fired up the burp and started intercepting the requests on a shopping site but found nothing, Now I observed that the website is using Razorpay gateway and sent some of the requests to my Repeater that look somewhat special to me ๐Ÿ˜‰๐Ÿ˜‰

After searching ๐Ÿ”Ž๐Ÿ”Ž all the requests, I saw a request that takes all โ€œMY EYESโ€ ๐Ÿ‘€๐Ÿ‘€๐Ÿ‘€ towards itโ€ฆ..

Payment Request thatโ€™ll be sent to UPI User

In this request, we can observe some parameters such as UPI ID, Description, Amount, etc.

After seeing the request, I came to know this is the request that user receives as a Payment request on their UPI Application ๐Ÿ™‚

Now Iโ€™m thinking ๐Ÿค”๐Ÿค” about how I should use this request and what to do with it, also I tried multiple things on it but no useโ€ฆ.. ๐Ÿคทโ€โ™‚๏ธ๐Ÿคทโ€โ™‚๏ธ

Nearly been 15 minutes, by mistake I forwarded this request to the repeater in Burpsuite then I was able to see the Payment Request on my phone!! so this means the payment link or request is still active ๐Ÿ˜…

I literally thought this was my only HOPE to get something ๐Ÿ˜๐Ÿ˜

Now immediately, I sent the same request to the Intruder in Burpsuite, and want to check ๐Ÿ˜ˆ๐Ÿ˜ˆ after sending the request to the Intruder it looks like thisโ€ฆ.

Also clear or remove all selections to make the request more clear.

Payment Request in Intruder

Now select the attack type as Sniper and go to the Payloads tab, Here select the payloads type as โ€œNull payloadsโ€.

For Null payloads, itโ€™ll ask how many payloads to generate and give your desired value. Iโ€™m giving as โ€œ100" for testing purposes you can give as you desire to tease your friends ๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚

Payload Type and No. of Payloads

Now you can see the button called โ€œStart Attackโ€, tap on it. >>>>>>>

Payment Requests in Phonepe

Booommmmmmmm๐Ÿ˜ˆ๐Ÿ˜ˆ now you can see that payment requests are sent to the given UPI ID ๐Ÿ˜‚๐Ÿคฃ๐Ÿ˜‚๐Ÿคฃ

Similarly, you can give the UPI ID of Paytm, Google Pay, etc on Razorpay Payment Gateway to flood the Application. ๐Ÿ˜‚๐Ÿ˜‚

PS: Just shared this write-up for Knowledge Purposes. So please be aware while exploiting it. Also, the bug has already been submitted to Razorpay via the HackerOne Platform and they marked it as Informational.

Also special thanks to Mayur Parmar, Hemant Patidar, Tarun Tandon, and Pavan Kumar Chinta

Hope you enjoyed this write-up and gained something good. Visit my profile for doubts and guidance ping me on LinkedIn.

Also, you guys can follow me on Medium

Thanks and Byeeโ€ฆ Happy hacking and Letโ€™s hack together๐Ÿ‘จโ€๐Ÿ’ป๐Ÿ˜ˆ

Sign up to discover human stories that deepen your understanding of the world.

--

--

Anudeep Vysyaraju
Anudeep Vysyaraju

Written by Anudeep Vysyaraju

Security Researcher and Bug Bounty Hunter

Responses (6)

Write a response