Slide 14 of 28
Part 3 · Attack ScenariosSlide 14
PART 3
Attack Scenarios
Slides 14–17 · OWASP examples in plain English
Slide 14 · Scenario 1
Bots hold all the tickets. Fans get nothing.
OWASP Scenario #1 — no purchase limit, no cart timeout, no bot detection.
📄 OWASP API Security Top 10 · 2023 · API6 · Scenario 1
SETUP
A ticketing platform’s purchase flow.

A ticketing platform allows: browse events → select seats → add to cart → enter payment → confirm purchase. Tickets are scarce — a sold-out venue with 10,000 seats.

The API has no per-account ticket limit, no minimum time between add-to-cart and purchase, no limit on simultaneous cart holds per session, and no CAPTCHA or human verification step.

The exploit: A bot operator prepares 500 accounts with saved payment methods. The instant the sale opens, all 500 accounts simultaneously add maximum-quantity tickets to cart. Within 3 seconds, 5,000 of the 10,000 tickets are held in bot carts. Within 30 seconds, all 10,000 are either purchased or held. The first human user to reach the purchase screen sees: Sorry, no tickets available. All remaining inventory appears on resale platforms within the hour at 3–5x face value.
What the server saw

Valid accounts. Valid tokens. Valid requests. No rate limit violated. No authentication failure. From a pure security perspective, nothing was wrong. From a business perspective, 10,000 real fans were excluded from a purchase they had every right to make.

← Back Scenario 2 →