Skip to content

[Security] Negative withdrawal amount credits bank account - money duplication (no sign validation) #149

Description

@Pajt9whauht283as

Security report (responsible disclosure - no public PoC details)

Private vulnerability reporting is not enabled on this repository and there is no SECURITY.md, so I am reporting here publicly per GitHub guidelines. Happy to share full details privately.

Summary

The qb-banking:server:withdraw callback accepts a negative amount with no server-side validation. A negative withdrawal CREDITS the attacker's shared bank account balance, and the balance can then be withdrawn as real cash - unlimited in-game money, no job/admin/existing balance required.

Affected code

  • server.lua:211 - CreateCallback('qb-banking:server:withdraw', ...)
    • server.lua:216 - local withdrawAmount = tonumber(data.amount) - no sign/type validation
    • server.lua:232 - if accountBalance < withdrawAmount then return ... - balance guard is bypassed by negative values (0 < -10000 is false, so the check passes)
  • server.lua:117-135 - internal RemoveMoney:
    • server.lua:127 - account_balance = account_balance - amount - subtracting a negative amount increases the balance
    • server.lua:131 - same negative math persisted via UPDATE bank_accounts SET account_balance = account_balance - ?

Impact

Repeat withdraw with negative amounts on your own shared account to grow its balance without limit, then withdraw positive to cash (server.lua:234 - Player.AddMoney('cash', withdrawAmount)). Any player can generate unlimited cash on any server using qb-banking.

Additional observation (same root cause)

Job/gang account authorization (server.lua:229-230) only checks job.name ~= accountName and not job.isboss - any regular member whose job name matches the account name can withdraw from the shared job account (e.g. any police officer can drain the police account). Combined with the negative amount bug, this also allows crediting job accounts.

Suggested fix

  1. Validate server-side in withdraw/deposit/transfer callbacks: reject non-numeric and amount <= 0 values.
  2. Add the same guard inside internal AddMoney/RemoveMoney (lines ~80-137) so the exported helpers cannot be misused by third-party resources either.

I can provide a full proof of concept privately. No exploit details have been published anywhere.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions