webProeasy

Обменник «У Апишечки»

bug-makers

Task: Node.js/Express currency exchange REST API where flag is revealed when USD balance exceeds 1000. Solution: Negative amount injection bypasses insufficient funds check and increases balance via subtraction of a negative number.

$ ls tags/ techniques/
business_logic_bypassnegative_value_injectioninsufficient_input_validation

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups