Primary Source
OWASP API Security Top 10 — 2023 · API6:2023 Unrestricted Access to Sensitive Business Flows
OWASP Foundation · owasp.org · 2023
The authoritative source for the definition, vulnerable patterns, example attack scenarios (ticket purchase flow, referral system farming, limited item purchase), and prevention guidance in this module. CWE references: CWE-799 (Improper Control of Interaction Frequency), CWE-770 (Allocation of Resources Without Limits or Throttling). This course is an independent study companion — not affiliated with or endorsed by OWASP.
Real Incidents
Ticketmaster / Taylor Swift Eras Tour Presale Collapse — November 2022
Multiple sources · November 2022 – January 2023
In November 2022, Ticketmaster opened a verified fan presale for Taylor Swift’s Eras Tour. An estimated 14 million fans registered. Bots used simultaneous multi-account cart holds to monopolize ticket inventory. The presale system was overwhelmed and the general public sale was cancelled entirely. Subsequent Senate Judiciary Committee hearings in January 2023 examined ticketing monopolies and bot abuse. Resale prices reached $2,000–$5,000 per ticket for face-value tickets priced at $49–$449. Referenced in slides 1, 11, 26. Primary sources: Senate Judiciary Committee hearing transcripts (January 24, 2023), news coverage from The New York Times, Rolling Stone, and The Guardian.
Nike SNKRS — Sneaker Bot Industry and Limited Release Abuse
Multiple industry reports · 2020–2023
Nike’s SNKRS app for limited-edition sneaker releases has been a persistent target for commercial bot operations. Reports estimate that 40%+ of traffic on major release days is automated. Limited releases sell out in under 10 seconds. Commercial bot software (AIO Bots, Cybersole, Wrath AIO, Kodai) sells for $300–$500 in license fees and has secondary markets where active licenses trade for $1,000+. Nike has implemented CAPTCHA, device fingerprinting, and randomized drop timing to counter bots — with limited effectiveness. Referenced in slides 13, 26. Primary sources: Imperva Bot Traffic Report 2022, industry reporting from Highsnobiety and StockX market data.
Technical References
Imperva Bad Bot Report 2023
Imperva Research Labs · imperva.com · 2023
Annual industry report covering automated bot traffic volume, bot operator tactics (residential proxies, browser automation, CAPTCHA-solving services), and industry-specific impact. Includes data on bot traffic percentages in retail and ticketing. Relevant to the bot ecosystem discussion in slides 7, 13, 21.
OWASP Automated Threats to Web Applications
OWASP Foundation · owasp.org/www-project-automated-threats-to-web-applications
A companion OWASP project cataloguing automated threat types relevant to API6: OAT-005 (Scalping — acquiring high-demand items), OAT-010 (Card Cracking), OAT-019 (Account Creation), OAT-021 (Denial of Inventory). The taxonomy directly supports the attack pattern classification in slides 9–13.
CAPTCHA-Solving Service Economics
Industry research · 2captcha.com, anti-captcha.com published pricing
CAPTCHA-solving services using human workers publish their pricing publicly. As of 2023: image CAPTCHA solving at $0.50–$1.00 per 1,000 solves, reCAPTCHA v2 at $1.00–$3.00 per 1,000 solves. This pricing data underlies the CAPTCHA limitation discussion in slide 22 and quiz question 5.
Bot Management Solutions — Cloudflare, DataDome, PerimeterX (Human)
Cloudflare · DataDome · Human Security (formerly PerimeterX) · 2023
Commercial bot detection and management platforms referenced in MIT 03 (device fingerprinting and behavioral detection). These platforms continuously update their detection models as bot operators adapt. Published technical documentation and case studies from these vendors inform the fingerprinting signals described in slide 21.
Further Reading
U.S. Senate Judiciary Committee — “That’s Me Trying to Get Tickets” Hearing (January 24, 2023)
U.S. Senate Judiciary Committee · January 2023
Congressional hearing examining the Ticketmaster/Taylor Swift presale collapse, ticketing industry monopoly, and bot abuse. Testimony from consumer advocates and ticketing industry representatives. The hearing title is a reference to a Taylor Swift lyric. Available in the Congressional Record and C-SPAN archives. Provides legislative context for the business and regulatory consequences of API6-class failures.
BETTER ONLINE TICKET SALES (BOTS) Act of 2016
U.S. Federal Trade Commission · Public Law 114-274 · 2016
U.S. federal law prohibiting the use of bots to circumvent security measures on ticketing websites. Rarely enforced. The gap between the 2016 law and the 2022 Ticketmaster incident illustrates that legal prohibition without technical enforcement is insufficient — the API itself must enforce the business constraint.
PortSwigger Web Security Academy — Business Logic Vulnerabilities
PortSwigger · portswigger.net/web-security/logic-flaws
Interactive labs covering business logic vulnerabilities including quantity manipulation, workflow bypass, and trust-based flaws. The quantity bypass lab directly illustrates the API6 Scenario 3 failure (UI-only limits). Recommended hands-on practice after completing this module.