webeasy
156 - Сломанный магазин (Broken Shop)
duckerz
Task: Telegram bot shop with insufficient balance to buy all flag parts. Solution: Exploit state desynchronization between web and Telegram interfaces - use stale callback_data with old price to confirm purchases at reduced cost.
$ ls tags/ techniques/
stale_callback_exploitationstate_desyncbusiness_logic_bypass
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]