Affiliate Disclosure
If you buy through our links, we may get a commission. Read our ethics policy.

In-app purchasing exploit discovered for OS X apps

Last updated

Coming on the heels of Apple's attempts to plug an iOS in-app purchasing exploit, the latest being a developer support document released on Friday, a similar workaround has reportedly been found for desktop programs running on OS X.

Discovered and implemented by the same Russian hacker who crafted the iOS in-app purchasing workaround, the so-called "In-Appstore for OS X" uses a similar receipt-spoofing method to bypass Apple's validation system to get paid content for free, reports The Next Web.

Alexey Borodin's newest exploit uses the same DNS server routing and receipt spoofing method outlined in previous reports to fool apps into validating dubious in-app purchases.

The system requires a user to install local certificates on their Mac and route purchases to a specially-created DNS server hosted by Borodin. The server, set up to be a replica of the Mac App Store, then sends back a spoofed receipt verification.


Screenshot of Borodin's "In-Appstore for OS X" exploit in action. | Source: The Next Web

According to Borodin some over 8.46 million transactions have been made with his spoofing method, though it is not clear if that number includes the new system targeting OS X. Apple has the option to push out a fix through Software Update and the Mac maker is on the verge of releasing its new OS X Mountain Lion with a host of security protocols including the Gatekeeper security system later in July.

On the same day of the OS X app hack's release, Apple sent out emails inviting iOS app developers to use the company's new protected receipt validation system to thwart last week's in-app purchasing exploit ahead of permanent solution expected in iOS 6.



15 Comments

tallest skil 14 Years · 43086 comments

Hey, all right. Looks like we might get a 10.8 GM 2.

drumrobot 15 Years · 32 comments

There are in-app purchases on OS X?

 

News to me... I should use the MAS more often. 

gazoobee 15 Years · 3753 comments

I remember being so happy when I heard that the iron curtain was falling and Russia would finally be a free, democratic law-abiding society.  

 

All that's come out of there since however is shit, crime, misogyny, pornography, and tacky jewellery.  So sad.  

 

No wonder it's the first place Assad's wife would think to flee to from Syria. 

douglas bailey 15 Years · 306 comments

They'ed probably only have to update the Mac App Store Application itself. And I doubt it would require a new GM. A new Mountain Lion GM is not going to fix any thing on Snow Leopard or Lion.

ljocampo 17 Years · 656 comments

And the cat & mouse games begin. again and again...