Infinite money logic flaw (Video solution, Audio)

  Рет қаралды 14,788

Michael Sommer

Michael Sommer

Күн бұрын

Пікірлер: 18
@omarelebiary8900
@omarelebiary8900 3 жыл бұрын
This lab is very complicated
@janwrona9539
@janwrona9539 2 жыл бұрын
My first though before seening you video was to use Grep - Extract , but this macro stuff is insane ! Thanks for your great content :)
@tbltjrd3918
@tbltjrd3918 2 ай бұрын
I don't understand why the get request to my account triggers the macro. After the macro testing part, going to intruder to spam the account page with get request seems unrelated.
@vilislacis3337
@vilislacis3337 Жыл бұрын
I didn't know about Macro Recorder, so I just ran Intruder about 7 times with increasing number of gift cards each time. After this, I had enough credit to get the jacket with a coupon applied.
@0x2fd
@0x2fd Жыл бұрын
same
@imamuddinalmustaqim8138
@imamuddinalmustaqim8138 Жыл бұрын
I dont understand, after success test macro with same order steps that |'ve followed, the intruder result decreases my money and doesn't increase, but rather the cart store increases
@vishalraj_bittu_3483
@vishalraj_bittu_3483 Жыл бұрын
same bhai
@gianb12
@gianb12 Жыл бұрын
como lo solucionaste?
@GG-go7jv
@GG-go7jv 9 ай бұрын
code change in length ==> so if you use length to extract gift code you fail sometimes and decrease money if you fail more than 1 on 3
@kiranbh4483
@kiranbh4483 3 жыл бұрын
i am not able to select those 5 end points
@yashikagupta6064
@yashikagupta6064 17 күн бұрын
use CTRL + CLICK
@JuanBotes
@JuanBotes 2 жыл бұрын
very educational burp lab - thanks \o/
@GG-go7jv
@GG-go7jv 9 ай бұрын
279 attack is enough with 30% coupon.
@落珰
@落珰 Жыл бұрын
谢谢你,虽然有些绕
@ilkerylmaz
@ilkerylmaz 4 ай бұрын
if you have not burpsuite professional get help from python :)
@vasumudiraj8327
@vasumudiraj8327 3 жыл бұрын
how you spell url....... hahahahahhahahahahahaha
@Fleeenz
@Fleeenz Жыл бұрын
With the initial store credit you can purchase 14 gift cards, it’s possible to send all 14 codes directly to /gift-card to speed up the whole process?
@vilislacis3337
@vilislacis3337 Жыл бұрын
No, you need to loop thru them and to 14 POSTs.
Authentication bypass via encryption oracle (Video solution, Audio)
12:25
Low level logic flaw (Video solution, Audio)
5:54
Michael Sommer
Рет қаралды 18 М.
Long Nails 💅🏻 #shorts
00:50
Mr DegrEE
Рет қаралды 17 МЛН
Business Logic 10 | Infinite Money Logic Flaw #portswigger
14:26
HMCyberAcademy
Рет қаралды 1,1 М.
Lab: Web cache poisoning with an unkeyed header
9:00
Jarno Timmermans
Рет қаралды 4,9 М.
Inconsistent handling of exceptional input (Video solution, Audio)
9:53