webProeasy
Обменник «У Апишечки»
bug-makers
Task: Node.js/Express currency exchange REST API where flag is revealed when USD balance exceeds 1000. Solution: Negative amount injection bypasses insufficient funds check and increases balance via subtraction of a negative number.
$ ls tags/ techniques/
business_logic_bypassnegative_value_injectioninsufficient_input_validation
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Точность+ (Tochnost+)— bug-makers
- [web][Pro]Слепая инъекция (Blind Injection)— bug-makers
- [web][Pro]Совсем слепая инъекция (Completely Blind Injection)— bug-makers
- [web][Pro]Блекджек на раздевание (Stripping Blackjack)— bug-makers
- [web][Pro]Flag Shop— hackerlab