Skip to main content

business-logic-vuln

Entry P1 category router for business logic testing. Use when workflow abuse, race conditions, pricing flaws, or multi-step state attacks matter more than parser-level input injection.

الانتقال إلى التثبيت

معلومات المصدر

المستودع
Kur1sulab/blackbox
آخر نشاط في المصدر
١٢ أغسطس ٢٠٢٦ في ١٥:١٧
لغة SKILL.md المكتشفة
الإنجليزية
النجوم
٣
التفرعات
١

خيارات التثبيت

يُحدَّد Prompt الذي يراجع المصدر أولًا بشكل افتراضي. يمكنك التبديل إلى أمر مباشر أو تنزيل نسخة محلية.

مراجعة ملفات المصدر

اقرأ SKILL.md وأي ملفات مرافقة يعرضها SkillsMP قبل أن تقرر التثبيت.

عرض SKILL.md

SKILL.md
تعليمات المصدر · معاينة للقراءة فقط
name
business-logic-vuln
description
Entry P1 category router for business logic testing. Use when workflow abuse, race conditions, pricing flaws, or multi-step state attacks matter more than parser-level input injection.
# Business Logic Router This is the routing entry point for business-logic and state-machine issues. ## When to Use - The target involves coupons, inventory, payment, approvals, quotas, invites, trials, or state transitions - The issue is not parser-level; it is about when checks happen and which business conditions are checked - You suspect race conditions, workflow bypass, price tampering, negative values, stacked discounts, or multi-step flaws ## Skill Map - [Business Logic Vulnerabilities](../hack-business-logic-vulnerabilities/SKILL.md) ## Recommended Flow 1. First map key business states and one-time actions 2. Then check for check-then-act windows, sequence dependencies, or missing cross-step authorization 3. If the chain depends on APIs, uploads, or object permissions, return to the corresponding router skill to complete the path ## Related Categories - [api-sec](../hack-api-sec/SKILL.md) - [auth-sec](../hack-auth-sec/SKILL.md) - [file-access-vuln](../hack-file-access-vuln/SKILL.md)
عرض على GitHub