webeasy

156 - Сломанный магазин (Broken Shop)

duckerz

Task: Telegram bot shop with insufficient balance to buy all flag parts. Solution: Exploit state desynchronization between web and Telegram interfaces - use stale callback_data with old price to confirm purchases at reduced cost.

$ ls tags/ techniques/
stale_callback_exploitationstate_desyncbusiness_logic_bypass

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]