Web Logic Auditor

Authorized testing of access-control and business-logic flaws that pattern scanners cannot find — IDOR/BOLA, broken function-level authorization, mass assignment, business-logic abuse, and race conditions. A reasoning-driven methodology (Subject×Object×Action matrices, state-machine modeling, invariant analysis) plus two helper tools: authz_diff.py (two-identity response differ) and race_probe.py (concurrency probe).

ptn1411 c99dddf 3 files · 17.6 KB Updated

File contents

ptn1411/skill/tree/main/web-logic-auditor commit c99dddfbc6

Frequently asked questions

npx skillmds@latest add ptn1411/web-logic-auditor