Medium severity Attack Technique

Race Condition Exploitation

Requests fired simultaneously slip past checks that assume operations run one at a time.

Overview

A time-of-check-to-time-of-use gap lets an attacker repeat a request across many parallel connections so the balance or quota is read before any of them writes.\nWallet double-spends, bonus abuse and coupon stacking are classic outcomes.\nAtomic transactions, server-side locks and idempotency keys close the window.

Indicators of Compromise

Signals that suggest this is present on a system.

  • Identical requests arriving within milliseconds
  • Balances briefly going negative
  • Bonus or promotional credits granted more than once

Controls that stop it

  • Rate Limit and Monitor Authentication

    Throttle failed logins per account and per source, apply exponential back-off, and alert on volumes that look like automation. Rate limit expensive endpoints such as search, password reset and OTP verification so they cannot be used for enumeration or denial of service. Logging without alerting is not monitoring.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used