9.1 Lab: Limit overrun Race conditions | 2023

This lab’s purchasing flow contains a race condition that enables you to purchase items for an unintended price. To solve the lab, successfully purchase a Lightweight L33t Leather Jacket

Karthikeyan Nagaraj
2 min readSep 25, 2023

Description

This lab’s purchasing flow contains a race condition that enables you to purchase items for an unintended price.

To solve the lab, successfully purchase a Lightweight L33t Leather Jacket.

You can log in to your account with the following credentials: wiener:peter.

IMPORTANT — Solving this lab requires Burp Suite 2023.9 or higher.

Solution

  1. Log In to your account using the credentials wiener:peter
  2. Add Lightweight L33t Leather Jacket to the cart
  3. Now Apply the coupon and capture the request on Burp
  4. Now send it to the repeater and turn off the Intercept
  5. Now click on the request and send it again to the repeater itself 27 times totally
  6. Now Right Click on any tab then click > add tab to group > create tab group
  7. Now Select all 27 tabs and Create it as a Group
  8. Now, go to the browser and remove any existing coupon code
  9. On the Burp repeater, right-click send and click send group in parallel
  10. Now, Check on the site, your coupon code will be reduced high

Incase of Queries, ask me in the Comment

If you would like to support me so that I could create more free content — https://www.buymeacoffee.com/cyberw1ng

Thank you for Reading!

Happy Hacking ~

Author: Karthikeyan Nagaraj ~ Cyberw1ng

Telegram Channel for Ethical Hacking Dumps — https://t.me/ethicalhackingessentials

--

--

Karthikeyan Nagaraj

Security Researcher | Bug Hunter | Web Pentester | CTF Player | TryHackme Top 1% | AI Researcher | Blockchain Developer