#alessandro.ricci

1 messages · Page 1 of 1 (latest)

toxic coveBOT
distant ice
#

Hello

#

Can you give me an example of what you are seeing?

#

An example request ID that is

median scarab
#

req_iO9nrDwy251G3C

#

Status 402

distant ice
#

And can you tell me what you mean by "suspicious" exactly?

median scarab
#

We don't call in any case that endpoint, we always use only stripe pages to make our customer pay, also we see as a source Python/3.11 aiohttp/3.8.4 we don't use any python client

distant ice
#

So this looks like an attempt to tokenize card information using your secret key. I can see it looks like you mostly use a plugin

#

Yep

#

Looks to me from a glance like somehow your secret key got leaked

median scarab
#

yes we use the official plugin

distant ice
#

So I'd recommend rolling your keys and updating your plugin with your new keys

median scarab
#

ok, i see also no further attempt to establish any other connection (except a test of mine)

#

we will update keys

#

how can this happens ? application is inside an azure container (env file is so protected) and we dont expose that key to browser

distant ice
#

I really can't say...

#

Somehow someone got their hands on your key, but I have no way of knowing how that would have happened...