pentest-business-logic
OfficialFind and validate business-logic vulnerabilities.
Authorjd-opensource
Version1.0.0
Installs0
System Documentation
What problem does it solve?
Identify and test business logic vulnerabilities that arise from flawed workflow enforcement, inappropriate rule validation, and brittle state-machine behavior in applications.
Core Features & Use Cases
- Workflow Mapping: Map multi-step processes (checkout, onboarding, approvals) from recon deliverables and source code, documenting expected state transitions and constraints.
- Rule Extraction: Identify server-side business constraints (pricing, quantity, role gating, time-based rules, discounts) to validate enforceability.
- Step Circumvention: Attempt to bypass prerequisite steps, reorder actions, or replay complete flows to verify server-side safeguards.
- Data Integrity Abuse: Submit boundary and crafted inputs (negative quantities, zero prices, type confusion) to reveal validation gaps.
- Function Limit Bypass: Test per-user or per-session limits (coupon uses, referrals, votes) under stress or parallel requests.
- File Upload Logic: Assess file type handling and payload boundaries for uploads, including polyglot considerations.
- Payment Testing: Validate price calculations, discounts, and payment state transitions across the flow.
Quick Start
Run a controlled business-logic security assessment on a target application by mapping workflows and validating constraints with Burp and Playwright.
Dependency Matrix
Required Modules
None requiredComponents
references
💻 Claude Code Installation
Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.
Please help me install this Skill: Name: pentest-business-logic Download link: https://github.com/jd-opensource/JoySafeter/archive/main.zip#pentest-business-logic Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
Agent Skills Search Helper
Install a tiny helper to your Agent, search and equip skill from 223,000+ vetted skills library on demand.