Offensive Security

Business Logic Testing

Paying less than the price. Using a discount twice. Approving your own request. Nothing is broken here, so no tool will tell you about it. We start from how your business is supposed to work and try to bend it.

Coverage

What we test

The final scope follows your application and its risks. These are the areas this assessment normally covers.

  • Workflow abuse

    Steps skipped, repeated or taken out of order, and states reached that the design does not account for.

  • Trust boundary violations

    Values the server accepts from the client when it should be deciding them itself: prices, totals, roles, identifiers, entitlements.

  • Race conditions

    Where they are relevant: concurrent requests against balances, stock, redemptions and actions meant to happen once.

  • Payment and order manipulation

    Quantities, currencies, refunds, vouchers and totals, tested for outcomes the business would not accept.

  • Abuse of intended functionality

    Features working exactly as built, used at a scale or in a direction nobody designed for.

Next step

Scope the right amount of testing

You do not need to choose a service before contacting us. Describe the application and we will map the work to it.

How testing worksAssessments and pricing

Ask about business logic

Send a paragraph about what you built. We will tell you what is worth testing.