Lab: Insufficient workflow validation
This lab makes flawed assumptions about the sequence of events in the purchasing workflow. To solve the lab, exploit this flaw to buy a "Lightweight l33t leather jacket".
You can access your own account using the following credentials:
- With Burp running, log in and buy any item that you can afford with your store credit.
Study the proxy history. Observe that when you place an order, the
POST /cart/checkoutrequest redirects you to an order confirmation page. Send
GET /cart/order-confirmation?order-confirmation=trueto Burp Repeater.
- Add the leather jacket to your basket.
- In Burp Repeater, resend the order confirmation request. Observe that the order is completed without the cost being deducted from your store credit and the lab is solved.