webeasy

Tsunami

alfactf

Task: Web shop with bonus system where bonus_amount is validated by string length (max 3 chars) but then converted to float. Solution: Use scientific notation (9e9 = 9 billion) to bypass length check and get unlimited balance to buy the flag item.

$ ls tags/ techniques/
Scientific notation bypass for length validationType confusion (string to float conversion)

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]