Race Conditions in Web Apps: Limit Checks and TOCTOU Bugs
Overview
Race conditions appear when two concurrent requests pass a check before either updates shared state. Classic outcomes include double-spending credits, reusing invitations, or bypassing rate/quantity limits.
What You Will Learn
• Hotspots
• Authorized testing approach
• Fixes

Hotspots
• Coupon/voucher redemption
• Wallet balances and inventory counters
• One-time invite or password-reset token consumption
• Follow/unfollow or like toggles with reward side effects
• Parallel API calls from mobile clients
Authorized testing approach
• Identify check-then-act flows in proxy history
• Send carefully controlled concurrent requests in a lab-like manner within scope
• Measure whether final state matches business rules
• Avoid load that looks like denial-of-service unless explicitly permitted
Remediation
• Atomic database operations and proper transactions
• Idempotency keys for sensitive actions
• Row-level locks or constraint-based enforcement at the data layer
• Server-side quotas that cannot be bypassed by parallelism
Conclusion
Use this guide only on systems you are authorized to test. At SapiensHack, we focus on clear methodology, solid notes, and findings that help teams fix real risk—not noisy scanner output.
If you want related reading, browse the matching category in the sidebar and continue the series from there.




Comments