1. Executive Summary & Scope
Webhooks allow external third parties (payment processors, cloud alerts, CI systems) to notify an application of asynchronous events. If an application processes webhook events without verifying the provider's cryptographic signature, attackers can forge fake payment confirmations or user events.
2. Threat Model & Attack Vectors
An attacker sends a fabricated webhook request claiming an invoice has been paid in full, unlocking digital products or services without actual financial transfer.
3. Code Analysis & Remediation Playbook
Vulnerable Implementation Pattern
Hardened Defense-in-Depth Implementation
4. Audit Verification Checklist & Pass Criteria
| Verification Phase | Audit Test Description | Mandatory Passing Criteria |
|---|---|---|
| Signature Tampering Test | Alter single character in webhook body while preserving signature. | Server rejects payload with 401 Unauthorized. |
| Timestamp Replay Defense | Inspect webhook payload for timestamp signature and enforce 5-minute replay window. | Replayed payloads older than 300 seconds are rejected. |
| Constant-Time Comparison | Verify code uses `hash_equals()` rather than standard `==` or `===`. | Prevents byte-by-byte timing attacks on HMAC signatures. |
WebOTG Application Security Directorate
WebOTG provides benchmark reference documentation, automated matrix evaluators, and security test harnesses for government digital platforms, WQMS architectures, and STQC compliance frameworks.