Business Logic Vulnerability
Business Logic Vulnerabilities - Overview
1. What "business logic" actually means
2. Why these are different from every other vuln class
3. Root cause, every time
4. Impact - depends entirely on what the flaw touches
5. Category 1 - Excessive trust in client-side controls
6. Category 2 - Failing to handle unconventional input
7. Category 3 - Flawed assumptions about user behavior
3a. "Once trusted, always trusted"
3b. "Users will always fill in mandatory fields"
3c. "Users will follow the steps in order"
8. Category 4 - Domain-specific flaws
9. Category 5 - Encryption oracle
10. Category 6 - Email address parser discrepancies
11. Testing checklist - run through this on any workflow
12. Preventing these in your own apps (dev side, worth knowing either way)
PreviousAuthentication Attacks LABS (Portswigger Academy)NextBusiness Logic Vulnerability (Labs: Portswigger Academy)
Last updated