Race Conditions (single-packet attack)
Exploit small timing windows where the app checks-then-acts, to double-spend, bypass limits, or over-redeem.
Tags: race, concurrency, logic
Level: advanced
Method
Find limit-bound actions
Coupons, gift-card redemption, withdrawals, vote/like, invite acceptance, 2FA/OTP submission - anything meant to happen 'once'.
Fire in parallel
Use Burp Repeater's parallel 'send group' or Turbo Intruder's single-packet attack to deliver many requests within the same window.
Tools: Burp Suite
Confirm the overshoot
Prove state that shouldn't exist: balance below zero, coupon applied twice, more redemptions than allowed.
Field notes
- The HTTP/2 single-packet attack removes network jitter - it's the reliable modern technique.
- Even 'idempotent' endpoints can race on the read-modify-write of a counter.