webmedium

Flag Shop

hackerlab

Task: Flask shop with balance system and user-created products. Solution: Negative price injection (-99) bypasses character limit validation, increasing buyer balance instead of decreasing it. Multi-account abuse to accumulate funds and buy the flag.

$ ls tags/ techniques/
negative_price_injectioninteger_manipulationmulti_account_abuse

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]