Business Logic

Business logic / authentication bypass / privilege escalation — POST body field tampering (role/is_admin/user_type), 2FA bypass via response manipulation, predictable TOTP seeds, hidden authorization headers, multi-step workflow tampering. For challenges tagged business_logic, privilege_escalation, 2fa_bypass, or auth_bypass that aren't pure IDOR/JWT.

purpleailab Updated

File contents

purpleailab/decepticon/tree/main/packages/decepticon/decepticon/skills/standard/exploit/web/business-logic commit 14548dc8f3

Frequently asked questions

npx skillmds@latest add purpleailab/business-logic