Race Condition
RACE CONDITIONS
What is Race conditions ?
Limit over run RC (Exploiting Logic Flaws)
This method required Burp version 2023.9.x or higher (This is the easiest method to exploit, you can create your own script also.)
Rate-Limit Bypass via RC
Multi-Endpoint Race Conditions
Single Endpoint RaceCondition
Time Sensitive Vulnerabilities
REAL World Cases : (H1 reports)
1 - Race condition in flag submission
2 - Race condition on Invite user action
3 - Race condition in performing retest allows duplicated payments
4 - Race Condition leads to Un-Deletable group member
5 - Race Condition when following a user
6 - Race Conditions in Popular reports feature.
7 - Race condition in joining CTF group
8 - Race conditions can be used to bypass invitation limit
9 - Race Condition allows to redeem multiple times gift cards.
Last updated
Was this helpful?