webPromedium

Flag Shop

hackerlab

Task: Flask shop with balance system and user-created products. Solution: Negative price injection (-99) bypasses character limit validation, increasing buyer balance instead of decreasing it. Multi-account abuse to accumulate funds and buy the flag.

$ ls tags/ techniques/
negative_price_injectioninteger_manipulationmulti_account_abuse

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups