Skip to content

Instantly share code, notes, and snippets.

View wanted1205's full-sized avatar

Sanskar Sharma wanted1205

View GitHub Profile
@wanted1205
wanted1205 / INTIGRITI-secure-Challenge_1.md
Last active October 20, 2022 21:12
INTIGRITI-Challenge

The goal of this challenge is to become the steal everyone's money, but there are some checks which needs to be bypassed.

Code

An attacker can give account number of victim on from post parameter and on to parameter attacker can use his account number.As there is no check for verifying that from account is user’s account only.

But we need to verify it too.