In-App Purchase hack

in our in-app purchase we found that the application send the receipt file to server for validation
the file is:
ewoJInNpZ25hdHVyZSIgPSAiQXJ1WHNBSTQ2eHRwNzJEK2drR3dsaVdkbk8vbEExSzN6Vi9XZnhNSnpB MDdjUlJwaTNWTmx
IZXZ0VnI5KytsbGZvSVArQ0JWNmdJNUxkcDJBNFdNM2EwUFZHeW9DUU16bEV4Z2Y3SnZrV3VBWEIzYld UUDBycHFndkcxeHAraUxnV
XBMR2ZtMVlYSkw5N0FmTDdwOUtQdmRpcGtrUGlnTFNHcjZXR2orRlZ3ckFBQURWekNDQTFNd2dnSTdvQ U1DQVFJQ0NHVVVrVTNaV0
FTMU1BMEdDU3FHU0liM0RRRUJCUVVBTUg4eEN6QUpCZ05WQkFZVEFsVlRNUk13RVFZRFZRUUtEQXBCY0 hCc1pTQkpibU11TVNZd0p
BWURWUVFMREIxQmNIQnNaU0JEWlhKMGFXWnBZMkYwYVc5dUlFRjFkR2h2Y21sMGVURXpNREVHQTFVRUF 3d3FRWEJ3YkdVZ2FWUj
FibVZ6SUZOMGIzSmxJRU5sY25ScFptbGpZWFJwYjI0Z1FYVjBhRzl5YVhSNU1CNFhEVEE1TURZeE5USX lNRFUxTmxvWERURTBNRFl4T
kRJeU1EVTFObG93WkRFak1DRUdBMVVFQXd3YVVIVnlZMmhoYzJWU1pXTmxhWEIwUTJWeWRHbG1hV05oZ EdVeEd6QVpCZ05WQkFz
TUVrRndjR3hsSUdsVWRXNWxjeUJUZEc5eVpURVRNQkVHQTFVRUNnd0tRWEJ3YkdVZ1NXNWpMakVMTUFr R0ExVUVCaE1DVlZNd2daO
HdEUVlKS29aSWh2Y05BUUVCQlFBRGdZMEFNSUdKQW9HQkFNclJqRjJjdDRJclNkaVRDaGFJMGc4cHd2L 2NtSHM4cC9Sd1YvcnQvOTF
YS1ZoTmw0WElCaW1LalFRTmZnSHNEczZ5anUrK0RyS0pFN3VLc3BoTWRkS1lmRkU1ckdYc0FkQkVqQnd SSXhleFRldngzSExFRkdBdDF
tb0t4NTA5ZGh4dGlJZERnSnYyWWFWczQ5QjB1SnZOZHk2U01xTk5MSHNETHpEUzlvWkhBZ01CQUFHamN qQndNQXdHQTFVZEV3RUIv
d1FDTUFBd0h3WURWUjBqQkJnd0ZvQVVOaDNvNHAyQzBnRVl0VEpyRHRkREM1RllRem93RGdZRFZSMFBB UUgvQkFRREFnZUFNQjBH
QTFVZERnUVdCQlNwZzRQeUdVakZQaEpYQ0JUTXphTittVjhrOVRBUUJnb3Foa2lHOTJOa0JnVUJCQUlG QURBTkJna3Foa2lHOXcwQkFR
VUZBQU9DQVFFQUVhU2JQanRtTjRDL0lCM1FFcEszMlJ4YWNDRFhkVlhBZVZSZVM1RmFaeGMrdDg4cFFQ OTNCaUF4dmRXLzNlVFNNR
1k1RmJlQVlMM2V0cVA1Z204d3JGb2pYMGlreVZSU3RRKy9BUTBLRWp0cUIwN2tMczlRVWU4Y3pSOFVHZ mRNMUV1bVYvVWd2RGQ0T
ndOWXhMUU1nNFdUUWZna1FRVnk4R1had1ZIZ2JFL1VDNlk3MDUzcEdYQms1MU5QTTN3b3hoZDNnU1JMd lhqK2xvSHNTdGNURXFlOXB
CRHBtRzUrc2s0dHcrR0szR01lRU41LytlMVFUOW5wL0tsMW5qK2FCdzdDMHhzeTBiRm5hQWQxY1NTNnh kb3J5L0NVdk02Z3RLc21uT09kcV
Rlc2JwMGJzOHNuNldxczBDOWRnY3hSSHVPTVoydG04bnBMVW03YXJnT1N6UT09IjsKCSJwdXJjaGFzZS 1pbmZvIiA9ICJld29KSW05eWF
XZHBibUZzTFhCMWNtTm9ZWE5sTFdSaGRHVXRjSE4wSWlBOUlDSXlNREV6TFRBNExURXlJREV6T2pNMk9 qQTJJRUZ0WlhKcFkyRXZU
Rzl6WDBGdVoyVnNaWE1pT3dvSkluQjFjbU5vWVhObExXUmhkR1V0YlhNaUlEMGdJakV6TnpZek16azNO alkxTkRNaU93b0pJblZ1YVhGMV
pTMXBaR1Z1ZEdsbWFXVnlJaUE5SUNKaVpEUTJObUZqWkRRNFpEbGtaalUzWlRRM1pUaGxOV1k0TVdZM1 lXWmxOV1l3WVRZMU56U
mtJanNLQ1NKdmNtbG5hVzVoYkMxMGNtRnVjMkZqZEdsdmJpMXBaQ0lnUFNBaU16VXdNREF3TURFNU56W XlORGcwSWpzS0NTSmlkbk
p6SWlBOUlDSXhMamN1TUNJN0Nna2lZWEJ3TFdsMFpXMHRhV1FpSUQwZ0lqUTNOelF4TkRBMU5DSTdDZ2 tpZEhKaGJuTmhZM1JwYjI0d
GFXUWlJRDBnSWpNMU1EQXdNREF4T1RjMk1qUTROQ0k3Q2draWNYVmhiblJwZEhraUlEMGdJakVpT3dvS kltOXlhV2RwYm1Gc0xYQjFjb
U5vWVhObExXUmhkR1V0YlhNaUlEMGdJakV6TnpZek16azNOalkxTkRNaU93b0pJblZ1YVhGMVpTMTJaV zVrYjNJdGFXUmxiblJwWm1sbG
NpSWdQU0FpUmtFeU56VTJNVVV0TWpnNVFpMDBPRGN4TFRrM01FSXRNVGt5UkVJeE5VSkdOMFZGSWpzS0 NTSnBkR1Z0TFdsa0lpQ
TlJQ0kwTnpnM056WTBOamNpT3dvSkluWmxjbk5wYjI0dFpYaDBaWEp1WVd3dGFXUmxiblJwWm1sbGNpS WdQU0FpTVRVMU5qQXhOel
FpT3dvSkluQnliMlIxWTNRdGFXUWlJRDBnSW1kaGJHRjRlVjlsYlhCcGNtVmZaR1ZzZFhobExqSTNOUz VrWVhKcmJXRjBkR1Z5Y3lJN0Nna2lj
SFZ5WTJoaGMyVXRaR0YwWlNJZ1BTQWlNakF4TXkwd09DMHhNaUF5TURvek5qb3dOaUJGZEdNdlIwMVVJ anNLQ1NKdmNtbG5hVzVoYkM
xd2RYSmphR0Z6WlMxa1lYUmxJaUE5SUNJeU1ERXpMVEE0TFRFeUlESXdPak0yT2pBMklFVjBZeTlIVFZ RaU93b0pJbUpwWkNJZ1BTQWlZ
Mjl0TG5SaGNEUm1kVzR1WjJGc1lYaDVaVzF3YVhKbExqRmlkV1ptSWpzS0NTSndkWEpqYUdGelpTMWtZ WFJsTFhCemRDSWdQU0FpTWp
BeE15MHdPQzB4TWlBeE16b3pOam93TmlCQmJXVnlhV05oTDB4dmMxOUJibWRsYkdWeklqc0tmUT09Ijs KCSJwb2QiID0gIjM1IjsKCSJzaWd
uaW5nLXN0YXR1cyIgPSAiMCI7Cn3====516226===
this file look like right and we send the file to apple server to validate, and the apple server return us this receipt is right.
but look carefully we found the receipt file is wrong the hacker add "==516226===" at last of the recepit file and he add the number for validation again each time when we send validate the apple server return is right.
in our server we have prevent one receipt file validated twice but hao could we avoid this condition。

To Contact iTunes Support and request assistance Click  Here

Similar Messages

  • My hotmail account was hacked, so the mail that I use to sign in in itunes also, it's the same. But if I create a new account how can I transfer the money and the apps purchased to the new account ?

    My hotmail account was hacked, so the mail that I use to sign in in itunes also, it's the same. But if I create a new account how can I transfer the money and the apps purchased to the new account ?
    I really need help ! I had around 30 $ in my account !

    Don't create a new iTunes account.
    Just update everything with new info/change password/ security questions.
    -> https://appleid.apple.com/

  • HT201303 Hi my iTunes account has been hacked by someone in Canada, they downloaded a game called "Game of War fire age" the game is free but the in app purchases are up to £69.99 each time for gold I am very concerned about the security of ITunes at this

    My iTunes account has been hacked via Canada according to an email from apple some one in china tried a few weeks ago but failed.
    I changed my password a couple time now but it seems that someone has hacked it and downloaded a free game called "game of war fire age" as I said its a free game but the in app purchases can be up to £69.99 per purchase of gold?
    This is a worrying thought that my account has been compromised and I am unsure of what to do about it.
    I would like to open a new account but would I be able to transfer all my purchases over to a new account any advice is welcome many thanks for your time.

    i recieved the same email with the same game and it also stated the purchase was from canada i have revieved a few other as well and am concerned i have changed my password a few times now but i still revcieve emails and am very worried. i recieved the email near the date this question had been put up
    however i do not know how they are downloading apps as my credit card details need verification when i download anything , any help would be much appreciated.

  • Account Hacked and In-App Purchases Charged

    I was charged for in-app purchases for an app I never downloaded.  The app is listed as a free app and therefore as best I can tell there is no course of action through Apple for getting the total ($43.56) refunded.  Anyone know of anything that can be done other than contacting the developer (Tap4Fun)?  I'm sure they will email me right back.

    Change your password.
    Contact iTunes Support, you can probably get a refund.

  • HT2075 I have been charged for over £135 of in app purchases that I haven't made. What can I do? I did email itunes 3days ago but had no response!!

    Help!!  I started recieving emails from ITunes with reciept for payments on Friday evening and they continued to come in till Sat morning. First thing I did was check with my family and no one has made the purchases. The receipts show the date as 12th October and as the children were at school then cubs AND they don't know the apple id, I really can't see how they could have done it. My husband is not in the slightest bit interested in Dragonvale or Tap Pet Hotel (he's also quite tight) so he definately wouldn't have done it.
    Is it possible for mistakes like this to happen or is there a possibility that my account has been hacked??
    I emailed itunes support on Sat 13th but despite their reassurance that they will respond within 48 hours I have heard nothing. I have tried to report a problem on each receipt but that doesn't seem to lead to any page.
    I have since changed my password and ensured that all the necessary restrictions are in place for in app purchases, but its made me want to delete all my apps and never download anything from itunes again, as it obviously isnt secure.
    Can anyone help?
    TTFN
    Sarah7550

    It can take a number of days before the refunds will show on your card - if they aren't there by the end of the week then try contacting iTunes Support again.

  • I have purchased a in app purchase of a 'gcsepod' for my little brother however the purchase does not come up in the app and requests me to buy another. How do i solve this? I have also got the receipt for this purchase.

    i have purchased a in app purchase of a 'gcsepod' for my little brother however the purchase does not come up in the app and requests me to buy another. How do i solve this? I have also got the receipt for this purchase.

    I'm not sure I can make sense of this but without asking too many questions, you can resolve your question by contacting iTunes direct.
    Apple - Support - iTunes - Contact Us
    But they will be wondering about the reference to hacking and you feeling bad about getting something for free.
    Best step in my view is to make sure you don't get similarly involved in future.  You must know roughly what you were doing.   Then writie it off to a not to be repeated experience.

  • In app purchase validation when offline

    How can I validate access to additional content downloaded via in-app purchasing when the device is offline?  A user should still be able to access those resources when offline.  In theory a hacker could copy an app's additional resources purchased legally, including the plist file, from one device to another and then access those resources on an offline device without a problem.
    My initial thought was to encrypt with the user's apple id at purchase time, but I can't get access to it.  I can't use the device id, that prevents sharing over the cloud.  Just storing the transaction receipt is insufficient, that could be copied to the new device.
    I know the problem would only occur for an offline device so perhaps it is not considered to be a major issue, but I would like to protect this additional content.  All the examples I've seen seem to assume a device will be online.
    Would a plist file copied in this way from one device to another still be work?  If so, is there a recommended way to protect additional resources or am I being too paranoid?
    Thanks in advance for any suggestions!

    This was a bug, as the Beta certificate was never deployed to the server.  I have worked to get that added and now you should be able to use the sample code, as is, and download the certificate without receiving a 404.
    https://lic.apps.microsoft.com/licensing/certificateserver/?cid=A656B9B1B3AA509EEA30222E6D5E7DBDA9822DCD
    Bret Bentzinger (MSFT) @awehellyeah

  • Did in app purchase in garageband to get sound loop and it says downloading but won't finishing loading

    i purchased garageband for free on the mac app store on my mac book air and then paid £2.99 in an in app purchase for sound loop it had a blue bar that is now filled but it stays like that and still says downloading it has been like this for 12 hours how do i fix it????

    I'm not sure I can make sense of this but without asking too many questions, you can resolve your question by contacting iTunes direct.
    Apple - Support - iTunes - Contact Us
    But they will be wondering about the reference to hacking and you feeling bad about getting something for free.
    Best step in my view is to make sure you don't get similarly involved in future.  You must know roughly what you were doing.   Then writie it off to a not to be repeated experience.

  • I have one apple ID for multiple devices in my family.  I'd like to keep it that way for itunes/app purchases.  I would like a simple step 1, step 2, step 3 response on what I need to do to separate all other features like imessage, contacts, emails, etc.

    I have one apple ID for multiple devices in my family.  I'd like to keep it that way for itunes/app purchases.  I would like a simple step 1, step 2, step 3 response on what I need to do to separate all other features like imessage, contacts, emails, etc.
    I have been reasearching how to do this on the internet, but I haven't found an easy explanation yet.  My family is going crazy over each others imessages being sent to others in the family and not being able to use FaceTime because of conflicting email addresses.  I have read that if each person gets their own iCloud account, this would work.  However, I need to know what to do after I set everyone up with their own iCloud account.  Do I make that the default email address to be contacted or can they still use their hotmail email addresses.  Any help- with easy explanation- would be much appreciated!!

    We do this in my family now.  We have one account for purchases, so it is used to share music and apps (I think that is in Settings/iTunes & App Stores).  Each iDevice has this configured.
    Then, each of us has our own iCloud account that is configured under Settings/iCloud.  That then allows us to have our own Mail/Contacts/Calendars/Reminders/Safari Bookmarks/Notes/Passbook/Photo Stream/Documents & Data/Find My iPhone/and Backup.  That Backup piece is pretty sweet and comes in handly if you replace your iDevice.  You can just restore from it.
    So we all share the Apple Store account but we all have our own iCloud accounts to keep the rest seperate or things like you mentioned are a nightmare.
    In answer to what iCloud does for you: http://www.apple.com/icloud/features/
    Think of it as an internet based ("cloud") area for all of those items listed in my response.  What you need to remember is photo stream only maintans the last 1000 pictures so don't count it as a complete backup solution for your pictures.  Even though I rarely sync with a computer these days, I do still try to sync my phone with iPhoto (I have an iMac) so that I have copies of all of my pictures.  1000 may not stretch as far as it sounds.
    Message was edited by: Michael Pardee

  • Help! I have a new iPhone 5s. My husband just lost his 4s, so I want to give him mine. Want to use same Apple ID so we both have access to itunes/apps purchases. Want to separate contacts, messages, mail, etc. I cannot change iCloud address.

    Help! I have a new iPhone 5s. My husband just lost his 4s, so I want to give him my 4s. We want to use same Apple ID so we both have access to itunes/apps purchases. Want to separate contacts, messages, mail, etc. I cannot change iCloud address on 4s iPhone. Also, when I tried to change iMessage I got a message that if I deleted my id (which seemed to be the only way to get my husband's I'd there), I would not be able to receive iMessages on any device.
    Would someone kindly tell me how to set up th 4s for my husband so that we can keep our info separate? It would be most appreciated! Thanks!!

    Hey Fagen!
    You will want to see the following article for guidance on achieving the result you wish to achieve:
    What to do before selling or giving away your iPhone, iPad, or iPod touch
    http://support.apple.com/kb/ht5661
    I would just follow the instructions from this article to give your unused 4s to your spouse. Since you have already started using your 5s, you will still be receiving iMessages on that phone and will have no need to receive them on a device that has been replaced. Thanks for coming to the Apple Support Communities!
    Cheers,
    Braden

  • In-app purchase of tangible goods

    Hi,
    I like apps that teach us and our kids.
    I also like in-app purchases. They allow developers to offer their apps for free with some partial (but very useful) content
    and make money with additional content/software that they sell as add-ons.
    I clearly see one missing component in this process:
    In-app purchase of tangible goods
    Imagine you are studying drawing on iPad.
    You are watching a training video. Instructor says:
    ”For the next lesson we will need the following Chinese 18 century brushes and acrylic paints. (shows picture of tools)
    You can buy them yourself in a local stationary store,
    OR
    You can click here and receive complete kit of brushes and paints necessary for this lesson for just $9.99.
    This kit also includes templates for practicing. Delivery will take only 3 working days"
    Another example:
    Imagine you are learning to cook Thai food on your iPad.
    You are watching a training video. Instructor says:
    ”To prepare the following Tom Yam recipe you would need the following fresh ingredients (meat, prawns)
    which you can buy in your local grocery store and the following traditional Thai herbs and spices. (shows picture and descriptions).
    Complete kit of Thai herbs and spices for this and other lessons is available as in-app purchase for just $4.99.
    Click here and we will deliver it to you in 3 working days"
    Is this something you would love to do in your app ?
    I think, Apple has everything necessary to make it a one click experience for users: calculate price including shipping and taxes,
    collect payment, send prepaid UPS label to app developer (or specified vendor).
    I wonder if this idea makes sense ?
    What do you think?
    Alex Goncharov
    Surrey, BC
    Canada

    ...or be responcible to do full refund and disable these in-app purchases if people will complain ?
    Would that work?

  • I bought a new app ($0.99), bought $19.00 worth of on app purchases and the app crashed, now it says that I have to start a new game since i had just started it and didn't get a chance to save it, so my question is, how do i get my money back?

    I bought a new app ($0.99), bought $19.00 worth of on app purchases and the app crashed, now it says that I have to start a new game since i had just started it and didn't get a chance to save it, so my question is, how do i get my money back?

    I'm keeping the app, i just need the $19.00 back.

  • Error reading when trying to make in app purchase

    I have the "isingworship" app and it will not let me purchase songs within the app... I made sure my in app purchase is turned on. 2 error messages come up when I try to purchase a song 1. We cannot connect to the iTunes store, and 2. please contact apple.come/support. The only reason I purchased and Ipad was to use this this app at our church and now it wont even work. Someone please help!

    Have you contacted iTunes Support ? If not then you can do so via this link and ask them why the message is appearing (we are fellow users here on these forums, we won't know why) : http://www.apple.com/support/itunes/contact/ - click on Contact iTunes Store Support on the right-hand side of the page, then Purchases, Billing & Redemption

  • What is the license for an App Store App?  In-App Purchase?  Re-downloads?

    Hello All!
    I purchased an iPhone 3G when they initially came out. My wife bought one (and uses my iTunes account on it exclusively) about six months later. I couldn't find and understand what the licensing agreement was about installing the same app on multiple devices. I wanted to be legal and do it right, but I knew I could download the same app on both phones (with a single purchase) since they both use the same iTunes account.
    I asked the iTunes store support via e-mail for a clarification of the policy since I couldn't find or understand the legal version of application licensing through the iTunes store on the Apple website. I got the run-around and no simple yes or no answer after several back and forth replies. So, I posted a message here and received a number of replies telling me that it was legal (not just possible, but LEGAL according to the EULA and the iTunes Store's licensing agreement -- which does vary considerably with each type of product sold). I proceeded accordingly since then based on that information, since I couldn't get a simple yes or no answer from iTunes Support about the really simple question I asked them. I was just attacked about my total ignorance on a different website by a user when I questioned the change in In-App purchase policies. I know Apple has seen a spike in these purchases, but it's been driven (quite literally) by the GPS app subscriptions, not true in-app product purchases.
    Up until now, I've avoided in-app purchaes because I just didn't like the fact that if it was lost due to some failure in hardware (or backups not working correctly, as that was a real problem with the iTunes software for some time for me), I had no ability to re-download it again, like the app itself. Now, with the policy change allowing for developers to avoid having to make a Lite version and make buying the full version an in-app purchase, this will make it unavoidable for certain applications if I want the full version.
    *So, I've got several questions, and would appreciate an Apple employee response, in addition to others who really know (and aren't just doing what is possible). Is it legal for a purchased app to be installed on multiple devices concurrently? If that is legal, can an in-app purchase be installed on multiple devices concurrently (and is possible to make this download without additional charges)? And finally, can in-app purchaes be downloaded again if there is a hardware failure (and no valid backup to restore from) or do I have to buy it all over? If that last question has an answer of no, it's going to help me determine who I buy from.*
    I'm not a fan of these in-app purchases since they weren't re-downloadable when problems occurred (as least that's what I was told), so as I said, I've avoided them. Obviously, I'm going to have to change that policy, but I want to know that my purchases will be safe. I like seeing the app on my computer's hard drive as a real file (and in iTunes as a listed application).
    I'd appreciate someone clearing this up for me as I took the first time I asked as a basis for my decisions since then and now I'm being told that was all wrong. I wish there was a simple link, in non-legal terminology, that would explain the licensing rights for each type of product being sold in the iTunes store on the Apple website itself. If there is such a place, iTunes Support should have told me about that when I contacted them in the first place when my wife first got her phone (but instead, I had to get answers here because it seemed like Apple's support is just automated computers guessing at appropriate responses to questions). It was such a simple question and I couldn't get an answer, even after 2 or 3 back and forth replies. It was rediculous!
    Would someone please clear this up for me?
    Thanks!
    Jim

    @wjosten:
    I really appreciate your input, but I'd like an Apple employee response to rest my hat on (like JasonL, who has responded to my posts previously -- his user account is marked with an Apple icon and says Apple Employee on it). I know it's not official, but after getting attacked on another website for this question, I knew I had to head here. I couldn't get straight answer from Apple's iTunes Store Support, so I wanted to have someone attached to Apple sticking their neck out.
    *A few questions for you, though, with the in-app purchases of both subsciptions (like with the GPS apps) and product additions, since I've never used them before because of fear of losing them. When you make an in-app purchase, and then I want to put it on my wife's phone, does it come up the same box saying it's free to download because you've already purchased it? How does this work with subscriptions, which would have to update the developer's servers somehow (to know how long to provide a service for)? I have MotionX GPS and need a subscription for esentially the app to work fully. I'm still in the 30-day free window, but it's not installed on my wife's phone. If I want to continue the service, will I be able to buy one subscription and just re-download it on her phone (and it would give her phone the same expiration date for her service from them)? Would it just update MotionX's system when the initial purchase is made and any additional downloads would be ignored (as long as they were made under my iTunes account)? This is particularly confusing because MotionX says you can stack subscriptions, so I would think each download would have to be paid for in order to do this. See what I mean?*
    *I know about music being non-redownloadable, but also thought the same was true for all media except for apps (movies, TV shows, etc.). Is that also not true? It's not a big issue for me, since I don't get most of my media from iTunes, but I'd like to know the right answers when I do.*
    Thanks for helping someone who doesn't understand Apple's SLA's or how to find them online on their system. Yes, I'm a PC, but am considering a Mac for the near future, but I've never had a lot of luck finding information in Apple's support knowledgebase at all. Microsoft's KB works better, but it just may be I'm used to it since I've used it for almost 20 years. I've only been using Apple's for going on 15 months.
    Really, if you can clear up these other questions, I'd be happy to call it solved. I appreciate it a bunch!
    Take care!
    Jim

  • After ios 8 update on ipad mini. None of my apps connect to app store for in app purchases.

    In app purchases worked before ios 8 update was installed on ipad mini. Restrictions are turned off. Can login to app store and purchase and download apps. Can't do in app purchases. Anybody else have this problem?

    We have read that any apps that use the google map app (removed by ios6) will not work.  We have lost a great camping app for this reason, and have heard that some weather apps are not working either.  The company line we've been given is it's up to the app developer to rewrite their apps.  ***** doesn't it.

Maybe you are looking for