vulns.co
/
GKData.io MCP

Billing and credits

Money movement is the price, credit, refund, or quantity the server stores. The client price is a claim. The finding is a ledger state the product should have rejected, on an object you own.

Skill: Billing and credits

Ask: Which amount did the server store, and does that ledger state match the rule the product claims?

Stop: One object you own shows the client amount and the stored amount. A shared balance was not drained.

Open the skill

Practice the class in the browser: PortSwigger Web Security Academy. The lab is theirs. This page is the stop condition and the disclosures.

Checklists

None linked for this class yet.

Disclosures

No public card yet.

Playbooks

  • Billing, credits, and refunds - The price that counts is the one the server stores. Change one money field on an object you own, compare it with the ledger, and stop.

Tools

  • Burp Suite - The industry-standard intercepting proxy for manual web testing. Community edition is free; Pro adds the active scanner and automation.

Questions

I changed the price in the request and the server stored it. What next?

Stop at that stored price. Name the object, the amount the client sent, and the amount the server kept. Do not repeat it across other customers' invoices.

A coupon applies twice if I send it in parallel. Is that this hunt?

The money object is this hunt. The timing window is the race hunt. Say which one you measured, and keep the proof on a balance you own.

This page is the linked pack hunt_brief("billing") returns on the MCP connector. Authorized testing only.