Sitemap
System Weakness

System Weakness is a publication that specialises in publishing upcoming writers in cybersecurity and ethical hacking space. Our security experts write to make the cyber universe more secure, one vulnerability at a time.

Business Logic Vulnerabilities (easy hit) Bug-Bounty

2 min readMay 10, 2022

--

Hello Cybersecurity Researchers,

I am back again with an amazing writeup for you all, So you all know me if not then let me introduce myself :

My Name is Mayank Gandhi I am a DevSecOps Engineer , Security Professional with 2.9 years of experience.

So I don't want to waste your time lets get back to the track and enjoy the bugs

In this writeup, we will see “ HOW TO FIND BUSINESS LOGIC BUGS ” And this article is specially dedicated for those who are facing some issues to find business logic vulnerabilities

1 — BROKEN AUTHENTICATION SESSION MANAGEMENT :

  • Let's suppose you are hunting on redacted.com
  • Go to the sign-up and login successfully
  • Visit My Profile
  • Fire up your burp suite
  • Update Your name or anything and Intercept the request
  • Send it to repeater
  • Now logout from the redacted.com
  • Again Go back to repeater
  • You can see your request which you previously sent it
  • Update any data in Repeater
  • Then again login
  • If information is updated there is a vulnerability
  • Boom !! You successfully find your first business logic bug !!

2– SESSION DOESNT EXPIRE AFTER PASSWORD CHANGE

Maybe you know this , No ? Don't worry I am here just follow the steps ..

  • You need one id and two browsers
  • Login with same id on two browsers
  • Let suppose Firefox and chrome
  • Change the password of the user in chrome
  • Go back to the Firefox browser
  • Update any information of user
  • If the information is updated or session is still live
  • Then there is a vulnerability
  • Boom !! You successfully find your Second business logic bug !!

3 - WEAK REGISTRATION CONFIRMATION TOKEN OVER HTTP

This is something different and so easy So just be patient and follow the steps ..

  • We need to register account
  • Then we’ll receive a verification email
  • Just copy that link paste into notepad
  • And You can see if the link is http or https
  • If the link is in http there is a vulnerability because http means non-secure and https means secure
  • Got it ? And here your found your third business logic bug !!

You need more writeups like this then comment it out , follow me for better updates and connect with me on LinkedIn

Get Mayank Gandhi’s stories in your inbox

Join Medium for free to get updates from this writer.

Don't forget to comment if you like this writeup and you need more like this

IF YOU ALSO WANT TO LEARN BUG BOUNTY FROM ME THEN ENROLL INTO MY UPCOMING BATCH JUNE And Grab your seat

Bonus — I will provide some job opportunities also to my students

FOLLOW ME ON OTHER PLATFORMS IF U LIKE THIS BLOG !!!

subscribe to my youtube channel for bug hunting related stuff : https://www.youtube.com/channel/UCh69B2L9ThUmSBN6a_1ul5Q

follow me on Instagram mr.mayankk_

follow me on Linkedin : https://www.linkedin.com/in/mayank-gandhi-b85725232/

Follow me on twitter : https://twitter.com/MayankG40326422

Signing off

Mayank

--

--

System Weakness
System Weakness

Published in System Weakness

System Weakness is a publication that specialises in publishing upcoming writers in cybersecurity and ethical hacking space. Our security experts write to make the cyber universe more secure, one vulnerability at a time.

Mayank Gandhi
Mayank Gandhi

Written by Mayank Gandhi

Founder & CEO at TMG Security || Cybersecurity Professional || Application Security || DevSecOps || Bug Bounty Hunter || VAPT || SecOps || SIEM || CyberSecurity