webPromedium
Throttle
alfactf
Task: Marketplace with gift certificates and expensive service requiring ~3.3M balance. Solution: Race condition on certificate creation - parallel requests bypass balance check, allowing unlimited certificate generation and redemption to accumulate funds.
$ ls tags/ techniques/
Race Condition on certificate creationTOCTOU (Time-of-check to time-of-use)Parallel HTTP requests to bypass balance check
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Booty— alfactf
- [web][Pro]YouTroopers— alfactf
- [web][Pro]Mermaid— alfactf
- [web][Pro]Tsunami— alfactf
- [web][Pro]Torrent— alfactf