top of page

Race Conditions in Web Apps: Limit Checks and TOCTOU Bugs

2 hours ago
1 min read

Overview


Race conditions appear when two concurrent requests pass a check before either updates shared state. Classic outcomes include double-spending credits, reusing invitations, or bypassing rate/quantity limits.


What You Will Learn


• Hotspots


• Authorized testing approach


• Fixes


Race Conditions in Web Apps: Limit Checks and TOCTOU Bugs

Hotspots


• Coupon/voucher redemption


• Wallet balances and inventory counters


• One-time invite or password-reset token consumption


• Follow/unfollow or like toggles with reward side effects


• Parallel API calls from mobile clients


Authorized testing approach


• Identify check-then-act flows in proxy history


• Send carefully controlled concurrent requests in a lab-like manner within scope


• Measure whether final state matches business rules


• Avoid load that looks like denial-of-service unless explicitly permitted


Remediation


• Atomic database operations and proper transactions


• Idempotency keys for sensitive actions


• Row-level locks or constraint-based enforcement at the data layer


• Server-side quotas that cannot be bypassed by parallelism


Conclusion


Use this guide only on systems you are authorized to test. At SapiensHack, we focus on clear methodology, solid notes, and findings that help teams fix real risk—not noisy scanner output.


If you want related reading, browse the matching category in the sidebar and continue the series from there.

Comments


© 2022 by SapiensHack.com (Security)

bottom of page