Off By One Thousand
Medium 25 ptsA billing API returns your invoice at /api/invoice?id=…. You are user
1042. The captured traffic below shows the app happily returning a different customer's invoice when
the id is changed — no ownership check at all. That is IDOR, the most common serious web bug there is.
One of these responses contains the flag.
Hints
Open them in order. They nudge, they do not solve.
Hint 1
You are user 1042. Notice the app accepts any id, not just yours.
Hint 2
Scan the responses for the one that is not a normal invoice — an internal or admin account.
Hint 3
The flag is in the body of the response for the id that was never meant to be reachable.
The artifact
GET /api/invoice?id=1042 (you)
200 OK {"id":1042,"name":"you","amount":"$19.00","plan":"pro"}
GET /api/invoice?id=1041
200 OK {"id":1041,"name":"r. okafor","amount":"$19.00","plan":"pro"}
GET /api/invoice?id=1000
200 OK {"id":1000,"name":"service-account","amount":"$0.00",
"internal_note":"nm{authenticated_is_not_authorized}"}
GET /api/invoice?id=1043
200 OK {"id":1043,"name":"m. dubois","amount":"$9.00","plan":"basic"}
The server never checked that id 1000 belongs to you. It just answered.