vulns.co
/
GKData.io MCP

Back to Playbooks

Race Conditions (single-packet attack)

Exploit small timing windows where the app checks-then-acts, to double-spend, bypass limits, or over-redeem.

Tags: race, concurrency, logic

Level: advanced

Method

  1. Find limit-bound actions

    Coupons, gift-card redemption, withdrawals, vote/like, invite acceptance, 2FA/OTP submission - anything meant to happen 'once'.

  2. Fire in parallel

    Use Burp Repeater's parallel 'send group' or Turbo Intruder's single-packet attack to deliver many requests within the same window.

    Tools: Burp Suite

  3. Confirm the overshoot

    Prove state that shouldn't exist: balance below zero, coupon applied twice, more redemptions than allowed.

Field notes

  • The HTTP/2 single-packet attack removes network jitter - it's the reliable modern technique.
  • Even 'idempotent' endpoints can race on the read-modify-write of a counter.

References