ctf.nitaimaarek.com Tracks Leaderboard Log in Sign up

Tracks / Server-Side Web Attacks / Off By One Thousand

Off By One Thousand

Medium 25 pts

A billing API returns your invoice at /api/invoice?id=…. You are user 1042. The captured traffic below shows the app happily returning a different customer's invoice when the id is changed — no ownership check at all. That is IDOR, the most common serious web bug there is. One of these responses contains the flag.

Hints

Open them in order. They nudge, they do not solve.

Hint 1

You are user 1042. Notice the app accepts any id, not just yours.

Hint 2

Scan the responses for the one that is not a normal invoice — an internal or admin account.

Hint 3

The flag is in the body of the response for the id that was never meant to be reachable.

The artifact

GET /api/invoice?id=1042   (you)
200 OK  {"id":1042,"name":"you","amount":"$19.00","plan":"pro"}

GET /api/invoice?id=1041
200 OK  {"id":1041,"name":"r. okafor","amount":"$19.00","plan":"pro"}

GET /api/invoice?id=1000
200 OK  {"id":1000,"name":"service-account","amount":"$0.00",
         "internal_note":"nm{authenticated_is_not_authorized}"}

GET /api/invoice?id=1043
200 OK  {"id":1043,"name":"m. dubois","amount":"$9.00","plan":"basic"}

The server never checked that id 1000 belongs to you. It just answered.

Submit the flag

You can solve it now, but to save the solve you need an account. Sign up or log in — it takes ten seconds.