webmedium

Throttle

alfactf

Task: Marketplace with gift certificates and expensive service requiring ~3.3M balance. Solution: Race condition on certificate creation - parallel requests bypass balance check, allowing unlimited certificate generation and redemption to accumulate funds.

$ ls tags/ techniques/
Race Condition on certificate creationTOCTOU (Time-of-check to time-of-use)Parallel HTTP requests to bypass balance check

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]