webPromedium
Lab 14 — SoundMart — Race Condition in Coupon Redemption
hackadvisor
Task: E-commerce store with coupon code system (SOUNDVIP, $500 fixed discount, limited uses). TOCTOU race condition in coupon redemption allows applying coupon beyond usage limit. Solution: Fire 50 concurrent requests via threading.Barrier to stack $5000 discount on $349.99 cart, then checkout triggers fraud detection revealing the flag.
$ ls tags/ techniques/
race_conditiontoctouconcurrent_requestsecommercecoupon_abuseexpress_sessionnegative_balancefraud_detection
race_condition_exploitationtoctou_coupon_bypassthread_barrier_synchronizationsession_cookie_sharingnegative_balance_trigger
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Lab 272 — SwiftMart — Race Condition in Promo Code Redemption— hackadvisor
- [web][Pro]Точка невозврата (Point of No Return)— hackerlab
- [web][Pro]Race Shop— web-kids20
- [web][Pro]Lab 193 — ShopNova — Price Manipulation in Checkout API— hackadvisor
- [web][free]Chocolate Drop— alfactf