BOOK THIS SPACE FOR AD
ARTICLE ADHi
I’m Xiaodong, a bounty hunter from China, and I’m eager to share with you an interesting vulnerability I discovered on a domestic platform. Let’s learn and exchange ideas together.
Let’s get started!
This time, the target was a reading app that allows us to subscribe to a membership at a low price on first use, enabling access to member-exclusive books.
You can enjoy 7 days of membership for just 1 ¥.
However, there’s a catch: this offer can only be enjoyed once per account.
Here’s where I started thinking: could I enjoy this offer multiple times?
Let’s do it!
I logged into the app on both of my iPhones and proceeded to the recharge section, stopping at the order confirmation page.
Then, I simultaneously clicked on “confirm order” on both devices, and something magical happened — I managed to enjoy the low-price offer twice!
This effectively bypassed the restriction that an account could only enjoy the offer once.
Thanks for watching!!!