Offensive Business Logic

Business logic vulnerability testing for web/mobile/API engagements. Covers workflow bypass, state machine violations, multi-step process abuse, price/quantity/discount manipulation, currency confusion, coupon stacking, refund/chargeback abuse, race conditions on logic boundaries, parameter tampering for hidden flows, role/tenant boundary violations, time-of-check vs use, anti-automation defeat, fraud-detection evasion, and subscription/quota abuse. Use when scoping an application after surface-level OWASP Top 10 has been covered, or when the asset is a transactional/marketplace/fintech/e-commerce/SaaS app where logic flaws produce direct financial impact.

thedixitjain a7a1812 13.1 KB Updated 2 repo stars

File contents

thedixitjain/the-mega-skill-library/tree/main/library/business-and-finance/offensive-business-logic commit a7a1812bf0

Frequently asked questions

npx skillmds add thedixitjain/offensive-business-logic