Education logo

The Shopify Hack: Dynamic Bundles

Shopify has become the de facto standard for e-commerce stores, thanks to its extensive ecosystem of apps that extend its functionality. One common feature in many online stores is bundles. Simple bundles offer a discounted collection of items, and depending on the implementation, a dynamic discount is applied. However, Shopify can only apply one discount at a time, meaning if you’ve already applied a discount, no other discount codes can be used. This can be problematic, especially in collaborations with influencers, where discount codes are used for tracking and incentives.

By ömer hakan ölçerPublished 2 years ago • 3 min read
The Shopify Hack: Dynamic Bundles
Photo by Lukas Blazek on Unsplash

What Could Be a Potential Workaround?

One potential workaround is to dynamically adjust item prices before they are added to the cart, meaning the prices are already discounted, and you can still apply a discount code. While discussing how this could be done, we also considered potential downsides and attack vectors. If prices are calculated dynamically, can they be hacked? Can the prices or discounts be altered?

Inspired by this idea, I began exploring several stores to see if these vulnerabilities existed. (I won’t share the specific stores to protect their security.) The hypothesis is that information about the price, discount, and how it is calculated is loaded from the server and used in the browser (client-side). This is especially interesting in cases where the discount amount increases as more items are added to the bundle or when the bundle is created dynamically (e.g., 3 items - 5%, 5 items - 10%).

Finding the Discount

The first task was to find the discount information, which was as simple as performing a search in the HTML source of the page.

Just changing the discount information directly usually doesn’t work. To effectively change it, you need to "debug" the website, meaning you have to intercept the loading process and modify it.

Chrome allows setting a breakpoint, which will pause the loading process when modifications are made to the page. This happens automatically when you load the page.

You have to resume loading a few times until the information becomes available. After changing the values and, in one case, executing the JavaScript to set the value, I was able to set my own discount and continue the execution. When I added items to the bundle, my discounts were applied. This should not be an issue if the discounts were calculated or at least validated server-side.

Testing on Shopify and WooCommerce

I tested this on several WooCommerce stores and found that although I could trick the frontend to show a different price, the correct discounted price was applied when the item was added to the cart. However, in some Shopify stores, this was not the case. The frontend (web application) determines and sets the price.

The prices shown here are from the order confirmation page, indicating that I could successfully submit the order and also received the confirmation email. The first thing I did was inform the corresponding stores. I also checked Shopify’s bug bounty program, but third-party apps/code are not eligible.

I only tested a few stores but found that this issue could be replicated in several others, suggesting that more stores could be vulnerable. Shopify gives their customers a lot of flexibility, but this also leads to many potential attack vectors. From my experience, most shop owners are non-techies and may not even know that this is possible.

Photo by Austin Distel on Unsplash

Ensuring Security for Your Shopify Store

If you have a Shopify store with a custom-built bundle builder, ensure that prices are at least validated server-side. Check with your team, agency, or reach out to me if needed.

Importance of Securing Your Store

Keeping your store secure and protected from potential attacks is crucial for maintaining customer satisfaction and business continuity. When using dynamic pricing and discount applications, it is essential to ensure these processes are validated server-side to provide an additional layer of security.

Security Measures and Practices

To keep your store secure, consider the following steps:

Server-Side Validation: Ensure dynamic pricing and discounts are validated server-side. This prevents client-side modifications from being valid.

Regular Security Testing: Regularly test your store’s security. This helps identify and fix potential vulnerabilities.

Professional Security Support: Seek support from security professionals. This provides expert recommendations and solutions to enhance your store’s security.

Conclusion

Shopify stores, with their extensive ecosystem and flexibility, offer excellent platforms for businesses. However, this flexibility can also introduce potential attack vectors. When using dynamic pricing and discounts, ensuring server-side validation is key to maintaining your store’s security. By taking the necessary precautions, you can enhance customer satisfaction and focus on growing your business. If you have any questions or need assistance, feel free to reach out to me or your team.

courses

About the Creator

Enjoyed the story? Support the Creator.

Subscribe for free to receive all their stories in your feed.

Subscribe For Free

Reader insights

Comments

There are no comments for this story

Be the first to respond and start the conversation.

Sign in to comment
    Written by ömer hakan ölçer