Invalid Model
Challenge
#1: Buy product for another price
Buy a product from the store for another price that is listed.
Solution
Create a custom post request on /api/Store/BuyProduct
with the following body.
You will find the flag in the response header.
#2: Create a transaction for another user
Create a transaction for another user.
Solution
Create a post request to Transaction/Create
with the following body. Don't forget about the RequestVerification token and cookie in your request.
You can find the flag in the response cookie.
Last updated