Testing For Business Logic Vulnerabilities
Overview
Cybersecurity skill for testing for business logic vulnerabilities. Follows industry best practices and security standards.
When to Use
Trigger phrases:
"testing for business logic vulnerabilities"
"Identifying flaws in application business logic that allow price manipulation, w"
During authorized penetration tests when automated scanners have found few technical vulnerabilities
When assessing e-commerce platforms for pricing, cart, and payment flow manipulations
For testing multi-step workflows (registration, checkout, approval processes) for bypass opportunities
When evaluating rate-limited features like vouchers, coupons, referrals, and rewards systems
During security assessments of financial applications, voting systems, or any application with critical business rules
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Authorization: Written penetration testing agreement covering business logic testing
- Burp Suite Professional: For intercepting and modifying multi-step request flows
- Application understanding: Thorough knowledge of the application's intended business workflows
- Multiple test accounts: Accounts at different privilege levels and states
- Browser DevTools: For examining client-side validation logic
- Documentation: Business requirements or user stories describing expected behavior
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Reconnaissance — Gather information about the target related to . Identify attack surface.
- Vulnerability Identification — Enumerate potential weaknesses using automated and manual techniques.
- Exploit Development/Selection — Use business logic vulnerabilities to identify and test vulnerabilities.
- Execution — Execute the test in a controlled manner with proper authorization.
- Post-Exploitation — Document the impact and extent of successful exploitation.
- Reporting — Write detailed findings with reproduction steps, impact assessment, and remediation guidance.
Tools
- business logic vulnerabilities — Primary tool for this skill
- Vulnerability Scanner — Automated weakness identification
- Exploitation Framework — Controlled exploitation testing
- Reporting Tool — Findings documentation and tracking
Process
- Reconnaissance — Gather target information, identify attack surface, enumerate services
- Analysis/Exploitation — Execute the technique, analyze results, document findings
- Reporting — Document IOCs, write findings, provide remediation recommendations
Verification
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: testing-for-business-logic-vulnerabilities3description: Use when identifying flaws in application business logic that allow price manipulation, workflow bypass, and privilege escalation beyond what technical vulnerability scanners can detect. Use when working with testing for business logic vulnerabilities.4license: Apache-2.05---67# Testing For Business Logic Vulnerabilities89## Overview1011Cybersecurity skill for testing for business logic vulnerabilities. Follows industry best practices and security standards.1213## When to Use14**Trigger phrases:**15- "testing for business logic vulnerabilities"16- "Identifying flaws in application business logic that allow price manipulation, w"171819- During authorized penetration tests when automated scanners have found few technical vulnerabilities20- When assessing e-commerce platforms for pricing, cart, and payment flow manipulations21- For testing multi-step workflows (registration, checkout, approval processes) for bypass opportunities22- When evaluating rate-limited features like vouchers, coupons, referrals, and rewards systems23- During security assessments of financial applications, voting systems, or any application with critical business rules242526## When NOT to Use2728- When you lack proper authorization for testing29- For production systems without change management30- When the task requires legal or compliance expertise beyond technical scope313233## Prerequisites3435- **Authorization**: Written penetration testing agreement covering business logic testing36- **Burp Suite Professional**: For intercepting and modifying multi-step request flows37- **Application understanding**: Thorough knowledge of the application's intended business workflows38- **Multiple test accounts**: Accounts at different privilege levels and states39- **Browser DevTools**: For examining client-side validation logic40- **Documentation**: Business requirements or user stories describing expected behavior4142## Workflow4344```python45# Example: IOC detection46import re4748IOC_PATTERNS = {49 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",50 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",51 "hash_md5": r"\b[a-f0-9]{32}\b",52 "hash_sha256": r"\b[a-f0-9]{64}\b",53}5455def extract_iocs(text: str) -> dict:56 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}57```58591. **Reconnaissance** — Gather information about the target related to . Identify attack surface.602. **Vulnerability Identification** — Enumerate potential weaknesses using automated and manual techniques.613. **Exploit Development/Selection** — Use business logic vulnerabilities to identify and test vulnerabilities.624. **Execution** — Execute the test in a controlled manner with proper authorization.635. **Post-Exploitation** — Document the impact and extent of successful exploitation.646. **Reporting** — Write detailed findings with reproduction steps, impact assessment, and remediation guidance.6566## Tools6768- **business logic vulnerabilities** — Primary tool for this skill69- **Vulnerability Scanner** — Automated weakness identification70- **Exploitation Framework** — Controlled exploitation testing71- **Reporting Tool** — Findings documentation and tracking727374## Process75761. **Reconnaissance** — Gather target information, identify attack surface, enumerate services771. **Analysis/Exploitation** — Execute the technique, analyze results, document findings781. **Reporting** — Document IOCs, write findings, provide remediation recommendations7980## Verification8182- [ ] All procedures executed completely and documented83- [ ] Findings validated against multiple data sources84- [ ] False positives identified and filtered85- [ ] Results documented with evidence and timestamps86- [ ] Recommendations provided with risk-based prioritization8788## Anti-Rationalization Table8990| Rationalization | Reality |91|---|---|92| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |93| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |94| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |