One Per Customer
Client: Stubhouse, a ticketing platform selling admission to concerts, festivals and dinners. Engagement: Black-box assessment of the Stubhouse customer site.
Scope
In scope: the Stubhouse application served at this origin and every HTTP endpoint it exposes.
Stubhouse has issued you one customer account for this engagement — username t.ferreira, password Gigs2026!. It is an ordinary account with no standing credit and no trade terms, and it is the only credential you have been given.
Out of scope: the hosting platform, the third-party payment provider Stubhouse hands balances to, other engagements, and denial of service.
Rules of engagement
This is an authorised exercise against a system Stubhouse controls. Reach the objective and stop — Stubhouse is paying for proof of impact, not for damage. Confine any change you make to what the objective requires, and stay inside the scope above.
Stubhouse has not released the application's source code for this engagement. Work from what the running system tells you.
Constraints
Stubhouse is not buying a code-guessing exercise. Enumerating promotional codes, wordlist scanning, and brute-forcing anything are out of scope, and a finding reached that way will not be accepted — every code you need is one the interface hands you. Neither are other customers' accounts and bookings in scope. The finding Stubhouse wants is one your own account can reach on its own.
Objective
Stubhouse makes two promises about what a booking costs. A promotional code is good for one use per customer, and the site declines a code an account has already redeemed. And whatever is still owed after any discount goes to the payment provider, so a ticket cannot be taken away from the box office without someone having paid for it.
The second promise is sound; nothing on this site can be made to pay you. Stubhouse has never checked the first one against what its own code does.
Disprove it: starting from the account above, confirm a booking for the Northwind Awards Dinner at £600.00 without a penny reaching the payment provider, and recover the collection code that booking prints. That code is what Stubhouse will accept as proof of impact. Submit it below to close the engagement.
Deliverable
Stubhouse wants a record of how you got there, not only the result. Log each request that moved the assessment forward in the Notes panel, and export the session when you are done.