webProeasy
Lab 193 — ShopNova — Price Manipulation in Checkout API
hackadvisor
Task: E-commerce platform where checkout API accepts client-controlled price in request body instead of validating server-side. Solution: Intercept checkout request and modify amount parameter to purchase premium membership for $0.01 instead of $9,999.99.
$ ls tags/ techniques/
business_logic_bypassclient_side_price_manipulationapi_parameter_tamperinginsecure_direct_object_reference
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Lab 61 — OrderNova — Negative Quantity Price Manipulation— hackadvisor
- [web][Pro]Lab 216 — ShelfWave — IDOR Price Manipulation in Checkout— hackadvisor
- [web][Pro]Flag Shop— hackerlab
- [web][Pro]Lab 14 — SoundMart — Race Condition in Coupon Redemption— hackadvisor
- [web][free]Chocolate Drop— alfactf