Hintru ENES ← All labs
✎

Improve lab

Improved version of Cheesy Does It β€” Business Logic Discount Abuse (Bugforge)

You are creating a new version of this lab. The original stays untouched. Your version will be signed by a cryptographic key generated in your browser β€” no email, no password. If you clear browser data without exporting your identity, you lose authorship over your contributions.

You do not have a signing identity yet in this browser.
1
Register, Log In & Identify the Discount Code
β–Ύ
πŸ’‘ Hint 1 β€” directional

Directional nudge β€” point at where to look without naming the technique.

🎯 Hint 2 β€” technique

Reveal the vulnerability class or technique without the exact payload.

πŸ”‘ Hint 3 β€” near solution

Near-solution: specific approach or command without the final flag.

2
Intercept the Purchase POST Request
β–Ύ
πŸ’‘ Hint 1 β€” directional

Directional nudge β€” point at where to look without naming the technique.

🎯 Hint 2 β€” technique

Reveal the vulnerability class or technique without the exact payload.

πŸ”‘ Hint 3 β€” near solution

Near-solution: specific approach or command without the final flag.

3
Explore Naive Bypass Attempts (Dead Ends)
β–Ύ
πŸ’‘ Hint 1 β€” directional

Directional nudge β€” point at where to look without naming the technique.

🎯 Hint 2 β€” technique

Reveal the vulnerability class or technique without the exact payload.

πŸ”‘ Hint 3 β€” near solution

Near-solution: specific approach or command without the final flag.

4
Manipulate How the Discount Field Is Sent
β–Ύ
πŸ’‘ Hint 1 β€” directional

Directional nudge β€” point at where to look without naming the technique.

🎯 Hint 2 β€” technique

Reveal the vulnerability class or technique without the exact payload.

πŸ”‘ Hint 3 β€” near solution

Near-solution: specific approach or command without the final flag.