0x17 - Exploiting Race Conditions
0x17 - Exploiting Race Conditions
Pentest Tips & Tricks
A01 - Broken Access Control
A01 - Broken Access Control
A02 - Cryptographic Failures
A02 - Cryptographic Failures
A03 - Injection Attacks
A03 - Injection Attacks
A04 – Insecure Design
A04 – Insecure Design
A05 – Security Misconfiguration
A05 – Security Misconfiguration
A06 – Vulnerable Components
A06 – Vulnerable Components
A07 – Identification and Authentication Failures
A07 – Identification and Authentication Failures
Recon & Attack Surface
Recon & Attack Surface
Tooling & Automation
Tooling & Automation
Creative, Strategic, and Mindset
Creative, Strategic, and Mindset
Bug Bounty $$$
Bug Bounty $$$
AI/ML/LLM/MCP
AI/ML/LLM/MCP
Latest Tips & Tricks
Latest Tips & Tricks
Did you know race conditions exploits are some of the best ways to bypass financial-related checks?
Race condition vulnerabilities abuse the server's (improper) way of handling concurrent requests.
They can be used to perform limit-overrun attacks such as:
using the same gift card multiple times
redeeming the same coupon code
bypassing a shop's quantity limits (Nvidia video cards 😉)
How to do it
Find the request that triggers the server-side check (i.e:
/api/check-coupon)Create a new tab group in
RepeaterAdd the same request multiple times to the group (
CTRL+R)Select
Send group in parallelRun the attack
Check if more than one response is valid
If you get more than one successful responses for the same coupon/gift card -> race condition was successful