Context#
Partner systems POST “payment captured” or “user provisioned” events. If the receiver accepts the same JSON twice and the signature still verifies (or there is no signature), an attacker who captured one callback can replay it to grant duplicate entitlements.
Theory#
Defense in depth uses HMAC with timestamp, unique event IDs stored server-side, and idempotent handlers. Weakness is often at the receiver, not the sender.
Practice#
- In a lab, capture one valid callback with Burp; replay unchanged; then replay with a new
Idempotency-Keyheader if the app honors it inconsistently.
Tools#
- Burp Suite Repeater