-
- Go to URL -
https://abc.target.com/product/121/checkout/promo
- Go to URL -
-
- Navigate to
Offer/Promo/Coupon code
option
- Navigate to
-
- Enter the random digit
-
Intercept the Request
and Send to intruder
-
- Apply payload &
Start attack
- Apply payload &
- Financial Loss, an attacker can easily bruteforce all promo/coupon/Offer codes.