Business Logic Mastery Roadmap: Workflow Abuse, Race Conditions, and Chaining
0 of 0 steps completed
Eleven phases, from fundamentals to chaining and exam prep. Each step has a checkbox and a list of resources. Tick steps as you finish them. Progress is saved in this browser. Logic bugs reward slow, careful workflow mapping, so take your time in Phases 2, 3, and 5.
Phase 1: Business Logic Fundamentals
Step 1.1 What business logic vulnerabilities are
- BookThe Web Application Hacker's Handbook, Chapter 11 (Attacking Application Logic), Stuttard and Pinto
- BookWeb Application Security, Andrew Hoffman (logic flaws chapters)
- PortSwiggerBusiness logic vulnerabilities learning path
- DocOWASP Business Logic Vulnerability
- YouTubeInsiderPhD, business logic bug bounty
Step 1.2 Why scanners cannot find them
Step 1.3 Threat modeling for logic bugs
- BookThreat Modeling: Designing for Security, Adam Shostack
- BookSecurity Engineering, Ross Anderson (protocol failures)
- DocOWASP Threat Modeling Cheat Sheet
Phase 2: Understanding Application Workflows
Step 2.1 Mapping multi-step flows
Step 2.2 Trust boundaries and client-side controls
- PortSwiggerExcessive trust in client-side controls
- PortSwiggerAccess control, URL-based manipulation
- HTB MachineE-commerce or SaaS web machines with checkout logic (retired list)
Step 2.3 State machines and workflow bypass
Phase 3: Price and Payment Manipulation
Step 3.1 Price tampering
- PortSwiggerPrice and quantity manipulation examples
- HackerOneHacktivity, price manipulation reports
- HTB MachineWeb machines with a checkout flow
Step 3.2 Coupon and discount abuse
- PortSwiggerDiscount and coupon logic examples
- HackerOneHacktivity, coupon and discount abuse reports
Step 3.3 Currency and rounding issues
- PortSwiggerHandling numeric and currency input safely
- HackerOneHacktivity, currency and rounding reports
Step 3.4 Refund and chargeback abuse
Phase 4: Authentication and Account Flows
Step 4.1 Password reset logic
- PortSwiggerAuthentication labs, password reset
- HTB AcademyLogin Brute Forcing and authentication attacks
- HackerOneHacktivity, password reset logic reports
Step 4.2 Account creation and verification flows
- PortSwiggerRegistration and verification logic
- HackerOneHacktivity, verification bypass reports
Step 4.3 Multi-step authentication bypass
- PortSwiggerMulti-factor authentication logic
- HackerOneHacktivity, 2FA bypass via logic
Step 4.4 Invite and referral abuse
Phase 5: Race Conditions
Step 5.1 Race condition fundamentals
Step 5.2 Time-of-check to time-of-use (TOCTOU)
- PortSwiggerLimit overrun and TOCTOU labs
- HackTricksRace condition techniques
- HackerOneHacktivity, race condition reports
Step 5.3 Multi-endpoint race conditions
- PortSwiggerMulti-endpoint and connection warming labs
- ToolTurbo Intruder scripts
Step 5.4 Rate limit bypass via race
- HackTricksRate limit bypass
- ToolTurbo Intruder, high-concurrency sending
Phase 6: Chaining Logic Bugs for High Impact
Step 6.1 IDOR chained with logic flaws
- PortSwiggerAccess control and IDOR labs
- HackerOneReport 111014, IDOR
- HackerOneReport 2268239, IDOR
Step 6.2 Logic flaw chained with CSRF and XSS
- PortSwiggerCSRF labs, combining with logic flaws
- HackerOneHacktivity, CSRF and logic chains
Step 6.3 Mass assignment chained with privilege escalation
Step 6.4 Business logic to full account takeover
Phase 7: High-Impact Company Targets
Step 7.1 Meta and Facebook
Step 7.2 Google
- ProgramGoogle Bug Hunters
- GitHubxdavidhu/awesome-google-vrp-writeups
Step 7.3 Shopify
- ProgramShopify Bug Bounty
- HackerOneHacktivity, Shopify logic reports
Step 7.4 GitLab
- ProgramGitLab Bug Bounty
- HackerOneReport 2056630, authentication bypass
Step 7.5 Netflix, Spotify, Okta, Tesla, Epic Games
- ProgramSpotify, Epic Games (check Netflix, Okta, and Tesla program pages for scope)
- GitHubdevanshbatham/Awesome-Bugbounty-Writeups
Phase 8: Tools and Programming
Step 8.1 Manual testing tools
- ToolBurp Suite (Repeater, Intruder, Sequencer, Turbo Intruder)
- ToolCaido, Postman, and OWASP ZAP
Step 8.2 Python for logic bug automation
- Toolrequests, pytest, and asyncio for custom workflow and race scripts
- DocRequests documentation
- GitHubKathanP19/HowToHunt, scripting references
Step 8.3 Race condition tooling
Phase 9: Books, Podcasts, and Videos
Step 9.1 Essential books
- BookThe Web Application Hacker's Handbook, Chapter 11, Stuttard and Pinto
- BookBug Bounty Bootcamp, Vickie Li (logic bug chapters)
- BookReal-World Bug Hunting, Peter Yaworski (logic bug chapters)
Step 9.2 Podcasts
- PodcastCritical Thinking Bug Bounty Podcast
- PodcastDarknet Diaries
- PodcastSecurity Now
Step 9.3 YouTube playlists and channels
- YouTubeInsiderPhD, STÖK
- YouTubeNahamSec, Jason Haddix
- YouTubePortSwigger, business logic and race condition labs
Phase 10: Labs and Practice
Step 10.1 HTB Academy and machines
- HTB AcademyWeb Attacks and related logic topics
- HTB MachineE-commerce or SaaS machines with multi-step flows
Step 10.2 PortSwigger Web Security Academy
- PortSwiggerAll business logic labs
- PortSwiggerAll race condition labs
- PortSwiggerAccess control and authentication labs
Step 10.3 CTF and bug bounty practice
Phase 11: Exam Preparation and Career
Step 11.1 CWES and CWEE business logic topics
- HTB AcademyCWES path logic and access control modules
- HTB AcademyCWEE path advanced logic and race topics
- PortSwiggerLogic labs as timed practice
Step 11.2 Bug bounty workflow
Phase 12: Emerging Patterns and CVEs
These three names are working labels for patterns that map onto known mechanisms (CWE-362 race conditions and CWE-840 business logic errors). Treat them as ways to structure testing, not as official standards.
Step 12.1 Action Limit Overrun (ALO)
- PatternExceed a per-user or per-resource action cap by sending requests concurrently so the limit check and the update race. Targets: single-use coupons redeemed many times, withdrawal or vote caps, one-per-account offers.
- PortSwiggerLimit overrun race conditions labs
- HackTricksRace condition techniques
- DocCWE-362, Concurrent Execution using Shared Resource
Step 12.2 Concurrent Workflow Order Bypass (CWOB)
- PatternDrive a multi-step flow out of its intended order, or run steps in parallel, so a state or permission check set in one step is skipped. Targets: finalizing an order before payment clears, confirming before approval, skipping a required gate.
- BlogJames Kettle, Smashing the State Machine
- PortSwiggerBypassing access controls using alternate paths
- DocCWE-840, Business Logic Errors
Step 12.3 Artifact Lifetime Exploitation (ALE)
- PatternAbuse the validity window or reuse of short-lived artifacts: password reset tokens, email verification links, signed URLs, invite codes, OAuth authorization codes, and cached responses. Targets: reusing a reset token, using a link after a role change, racing a token before expiry.
- PortSwiggerPassword reset and token handling, OAuth code reuse
- HackerOneHacktivity, token reuse and expiry reports
- CVECVE-2023-7028, GitLab account takeover via password reset to an unverified email