webmedium

Арифметика (Arithmetic)

duckerz

Task: Web app with daily math problems giving 1 coin each, flag costs 600 coins. Solution: Race condition in /api/check_answer endpoint allows earning multiple coins per request by sending parallel requests before cooldown is set.

$ ls tags/ techniques/
race_condition_exploitparallel_requeststoken_farming

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]