How I turned Membership into a Paycheck
作者分享了如何通过利用Chess.com应用程序中的漏洞,在解谜时记录正确移动并重复使用这些移动来完成不同挑战。通过这种方式,作者成功登上排行榜,并揭示了应用程序中未及时发送移动数据的机制。 2025-11-9 09:19:55 Author: infosecwriteups.com(查看原文) 阅读量:35 收藏

StvRoot

Welcome Back Hunters!

In my previous story I shared how I got my first bounty (membership) from chess.com and if you haven’t read that already I will drop it below towards the end.

Free Link for friends

Press enter or click to view image in full size

Photo by Growtika on Unsplash

Since, I got the membership I can fully test all the features without any restrictions and by doing so I ended by on the leaderboard.

Press enter or click to view image in full size

All the puzzles are rated low and I didn’t even solve one

What the app was doing that I exploited?

When solving the puzzles — any format — survival, 3 mins or 5 mins, the moves you are making are not sent to server right away!

When you loose after 3 strikes, all your moves are then sent via an api call.

Press enter or click to view image in full size

The catch is the challenge id. Every form has one and if we capture the game with correct moves and use them later changing this challengeID we can…


文章来源: https://infosecwriteups.com/how-i-turned-membership-into-a-paycheck-a4e90afac2cc?source=rss----7b722bfd1b8d---4
如有侵权请联系:admin#unsafe.sh