webPromedium
Точка невозврата (Point of No Return)
hackerlab
Task: Shop with voucher system where flag costs 1337$ but balance is only 1000$. Solution: Combined IDOR (uid parameter manipulation) with race condition to redeem vouchers multiple times, gaining enough balance to purchase the flag.
$ ls tags/ techniques/
race_conditiontoctousession_manipulationbalance_manipulationidorinsecure_direct_object_referenceconcurrent_requestsvoucher_systemthreadingshop_exploitation
Race Condition via concurrent voucher redemptionIDOR exploitation via uid parameter manipulationMulti-session attack coordinationThread synchronization with Barrier
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Lab 14 — SoundMart — Race Condition in Coupon Redemption— hackadvisor
- [web][Pro]Race Shop— web-kids20
- [web][Pro]Lab 272 — SwiftMart — Race Condition in Promo Code Redemption— hackadvisor
- [misc][Pro]RUCTFE— spbctf
- [web][Pro]Сила воли (Willpower)— duckerz