vulns.co
/
GKData.io MCP

Back to Playbooks

Billing, credits, and refunds

The price that counts is the one the server stores. Change one money field on an object you own, compare it with the ledger, and stop.

Tags: billing, refund, logic

Level: intermediate

Method

  1. Name the money object

    Credit, invoice line, refund, coupon, or quantity. Write the amount the UI shows before you change the request.

    Tools: Burp Suite

  2. Client price versus stored price

    Send a different amount on a checkout or update you are allowed to make. If the server stores your amount, that is the note. If it recomputes, record the recomputed value as the control.

    Tools: Burp Suite

  3. One replay

    Submit a completed refund or redemption a second time on your object. A second ledger line is the bug. Stop there.

    Tools: Burp Suite

  4. Quantity and currency

    Zero, a negative, and a second currency are separate questions. Record which one the server accepted. Do not iterate a range.

    Tools: Burp Suite

  5. Hand the race to the race brief

    If the interesting case is two requests in the same window, continue on the race hunt with a balance you own. Do not drain a shared pool.

    Tools: browser

Field notes

  • A price hidden in JavaScript is a claim. The stored invoice is the evidence.
  • Refunds of other customers' payments are out.
  • Say the currency and the amount. Do not predict a payout.

References