Billing, credits, and refunds
The price that counts is the one the server stores. Change one money field on an object you own, compare it with the ledger, and stop.
Tags: billing, refund, logic
Level: intermediate
Method
Name the money object
Credit, invoice line, refund, coupon, or quantity. Write the amount the UI shows before you change the request.
Tools: Burp Suite
Client price versus stored price
Send a different amount on a checkout or update you are allowed to make. If the server stores your amount, that is the note. If it recomputes, record the recomputed value as the control.
Tools: Burp Suite
One replay
Submit a completed refund or redemption a second time on your object. A second ledger line is the bug. Stop there.
Tools: Burp Suite
Quantity and currency
Zero, a negative, and a second currency are separate questions. Record which one the server accepted. Do not iterate a range.
Tools: Burp Suite
Hand the race to the race brief
If the interesting case is two requests in the same window, continue on the race hunt with a balance you own. Do not drain a shared pool.
Tools: browser
Field notes
- A price hidden in JavaScript is a claim. The stored invoice is the evidence.
- Refunds of other customers' payments are out.
- Say the currency and the amount. Do not predict a payout.