python-scripting

1 article
sort: new top best
clear filter
0 6/10

A bug bounty writeup describing the exploitation of a race condition combined with business logic flaws in a payment application to bypass deposit minimums and credit balance without valid bank transactions. The attacker leveraged concurrent requests with stolen/reused tokens to exploit a time-of-check-time-of-use vulnerability where the server failed to synchronize balance and minimum deposit validation across threads.

HackerOne Oleksandr Opanasiuk aaronhnatiw/race-the-web
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 17 hours ago · details