What problem does it solve?
It helps you uncover business logic vulnerabilities in web applications where attackers can manipulate verification, rate limits, or payment/state transitions to create real financial, privacy, or access impact.
Core Features & Use Cases
- Guided hunting for business logic weaknesses across authentication boundaries, verification gates, and transactional flows.
- Targeted checks for common root causes like client-trusted amounts, spoofable rate limiting headers, missing webhook signature validation, and unprotected internal/employee surfaces.
- Reproducible methodology that emphasizes proof of what an attacker can do, what the victim loses, and whether the impact is achievable quickly from scratch.
Quick Start
Use hunt-business-logic to plan and run a business-logic vulnerability hunt against your target by mapping authentication boundaries, identifying verification and callback flows, and testing for step-skip, header-spoofed rate limit bypass, and payment/webhook validation failures.