hunt-business-logic

Identify business logic vulnerabilities in e-commerce and payment systems.

1.1k|191|Updated Jun 24, 2026
One-click install
npx skills add https://github.com/uphiago/recon-skills --skill hunt-business-logic-uphiago
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: hunt-business-logic
Source: https://github.com/uphiago/recon-skills/tree/main/redteam/hunt-business-logic
Command: npx skills add https://github.com/uphiago/recon-skills --skill hunt-business-logic-uphiago

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill addresses the gap left by automated security scanners, which fail to detect nuanced business logic vulnerabilities that can lead to direct financial loss, unauthorized access, or service abuse. It provides a structured, field-validated approach to identifying these high-impact flaws that are often missed in standard testing workflows.

Core Features & Use Cases

  • Field-Validated Methodology: Built from 12 real public bug bounty reports with confirmed financial impact, covering proven high-payout patterns like coupon race stacking, price tampering, verification bypass, and payment webhook abuse.
  • Targeted Attack Surface Guidance: Includes specific URL patterns, response signals, JS patterns, and tech stack indicators to quickly identify vulnerable endpoints in e-commerce, SaaS, marketplace, and payment processing platforms.
  • Actionable Testing Workflows: Step-by-step hunting methodology, ready-to-use payloads, bypass techniques for common defenses, and a pre-report validation gate to ensure findings have concrete, reproducible impact.
  • Use Case: A bug bounty hunter testing an e-commerce platform can use this Skill to systematically identify price tampering flaws in the checkout flow, bypass email verification gates, and test for payment webhook signature validation gaps to submit high-severity, financially impactful reports.

Quick Start

Use the hunt-business-logic skill to systematically test an e-commerce checkout flow for price tampering and verification bypass vulnerabilities.

Frequently Asked Questions about hunt-business-logic

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find business logic flaws that automated security scanners miss?

Hunt business logic flaws by applying a field-validated methodology to e-commerce, SaaS, and payment platforms, systematically testing checkout flows, verification gates, and payment webhooks for high-impact financial vulnerabilities like price tampering and rate limit evasion.

How do I test for price tampering vulnerabilities in an e-commerce checkout flow?

Test for price tampering in an e-commerce checkout flow by manipulating request parameters, identifying vulnerable URL patterns, and using ready-to-use payloads to alter final transaction values. A pre-report validation gate ensures the finding has concrete, reproducible financial impact.

What is the best way to bypass email verification gates during penetration testing?

The best way to bypass email verification gates is to target specific response signals and JavaScript patterns using step-by-step hunting workflows. This methodology provides bypass techniques for common defenses to achieve unauthorized access in SaaS and marketplace applications.

How do I test payment webhook signature validation for bug bounty reports?

Test payment webhook signature validation by analyzing tech stack indicators and endpoint behaviors to identify signature validation gaps. Use actionable testing workflows to demonstrate payment webhook abuse, ensuring high-severity, financially impactful bug bounty reports.

Can I use this methodology for penetration testing SaaS applications and marketplace services?

Yes, this methodology applies directly to penetration testing SaaS applications and marketplace services. It includes targeted attack surface guidance with specific URL patterns and tech stack indicators to identify vulnerable endpoints in these platforms.

Why do standard automated security scanners fail to detect business logic vulnerabilities?

Standard automated security scanners fail to detect business logic vulnerabilities because they cannot understand nuanced application context, leaving gaps for direct financial loss. A field-validated approach built from real bug bounty reports is required to identify these high-impact flaws.