Offensive Security
Business Logic Testing
Paying less than the price. Using a discount twice. Approving your own request. Nothing is broken here, so no tool will tell you about it. We start from how your business is supposed to work and try to bend it.
Coverage
What we test
The final scope follows your application and its risks. These are the areas this assessment normally covers.
-
Workflow abuse
Steps skipped, repeated or taken out of order, and states reached that the design does not account for.
-
Trust boundary violations
Values the server accepts from the client when it should be deciding them itself: prices, totals, roles, identifiers, entitlements.
-
Race conditions
Where they are relevant: concurrent requests against balances, stock, redemptions and actions meant to happen once.
-
Payment and order manipulation
Quantities, currencies, refunds, vouchers and totals, tested for outcomes the business would not accept.
-
Abuse of intended functionality
Features working exactly as built, used at a scale or in a direction nobody designed for.
Next step
Scope the right amount of testing
You do not need to choose a service before contacting us. Describe the application and we will map the work to it.
Ask about business logic
Send a paragraph about what you built. We will tell you what is worth testing.