webPromedium
Flag Shop
hackerlab
Task: Flask shop with balance system and user-created products. Solution: Negative price injection (-99) bypasses character limit validation, increasing buyer balance instead of decreasing it. Multi-account abuse to accumulate funds and buy the flag.
$ ls tags/ techniques/
negative_price_injectioninteger_manipulationmulti_account_abuse
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Lab 193 — ShopNova — Price Manipulation in Checkout API— hackadvisor
- [web][Pro]Магазин (Gadget Shop)— hl_hacker
- [web][Pro]Lab 61 — OrderNova — Negative Quantity Price Manipulation— hackadvisor
- [web][Pro]156 - Сломанный магазин (Broken Shop)— duckerz
- [pwn][Pro]HackerLab: Simple BOF - Я хочу купить этот флаг!!!— hackerlab