0 of 0 steps completed

Eleven phases, from fundamentals to chaining and exam prep. Each step has a checkbox and a list of resources. Tick steps as you finish them. Progress is saved in this browser. Logic bugs reward slow, careful workflow mapping, so take your time in Phases 2, 3, and 5.

Phase 1: Business Logic Fundamentals

Step 1.1 What business logic vulnerabilities are
Step 1.2 Why scanners cannot find them
Step 1.3 Threat modeling for logic bugs

Phase 2: Understanding Application Workflows

Step 2.1 Mapping multi-step flows
Step 2.2 Trust boundaries and client-side controls
Step 2.3 State machines and workflow bypass

Phase 3: Price and Payment Manipulation

Step 3.1 Price tampering
Step 3.2 Coupon and discount abuse
Step 3.3 Currency and rounding issues
Step 3.4 Refund and chargeback abuse

Phase 4: Authentication and Account Flows

Step 4.1 Password reset logic
Step 4.2 Account creation and verification flows
Step 4.3 Multi-step authentication bypass
Step 4.4 Invite and referral abuse

Phase 5: Race Conditions

Step 5.1 Race condition fundamentals
Step 5.2 Time-of-check to time-of-use (TOCTOU)
Step 5.3 Multi-endpoint race conditions
Step 5.4 Rate limit bypass via race

Phase 6: Chaining Logic Bugs for High Impact

Step 6.1 IDOR chained with logic flaws
Step 6.2 Logic flaw chained with CSRF and XSS
Step 6.3 Mass assignment chained with privilege escalation
Step 6.4 Business logic to full account takeover

Phase 7: High-Impact Company Targets

Step 7.1 Meta and Facebook
Step 7.2 Google
Step 7.3 Shopify
Step 7.4 GitLab
Step 7.5 Netflix, Spotify, Okta, Tesla, Epic Games

Phase 8: Tools and Programming

Step 8.1 Manual testing tools
Step 8.2 Python for logic bug automation
Step 8.3 Race condition tooling

Phase 9: Books, Podcasts, and Videos

Step 9.1 Essential books
  • BookThe Web Application Hacker's Handbook, Chapter 11, Stuttard and Pinto
  • BookBug Bounty Bootcamp, Vickie Li (logic bug chapters)
  • BookReal-World Bug Hunting, Peter Yaworski (logic bug chapters)
Step 9.2 Podcasts
Step 9.3 YouTube playlists and channels

Phase 10: Labs and Practice

Step 10.1 HTB Academy and machines
Step 10.2 PortSwigger Web Security Academy
Step 10.3 CTF and bug bounty practice

Phase 11: Exam Preparation and Career

Step 11.1 CWES and CWEE business logic topics
Step 11.2 Bug bounty workflow

Phase 12: Emerging Patterns and CVEs

These three names are working labels for patterns that map onto known mechanisms (CWE-362 race conditions and CWE-840 business logic errors). Treat them as ways to structure testing, not as official standards.

Step 12.1 Action Limit Overrun (ALO)
Step 12.2 Concurrent Workflow Order Bypass (CWOB)
Step 12.3 Artifact Lifetime Exploitation (ALE)
Step 12.4 Recent CVEs to study