Understanding Business logic flaw
What it is
A business-logic flaw breaks no technical control — it exploits a gap in the rules the application enforces. A negative quantity, a coupon applied twice, a step reached out of order, a limit checked in the wrong place: the request is well-formed, but the outcome is one the business never intended.
How you approach it
- Map the intended flow, then ask what it assumes. That each step happens once? In order? That a number is positive?
- Break exactly one assumption with a request that is otherwise completely valid — the server validates the shape, not the intent.
- The flag is behind a state the flow was designed never to reach. Reach it anyway.
How it gets fixed
Every request was valid on its own; the flaw was in the sequence and the assumptions between them. Violating one unstated assumption produced a state the design ruled out, and the flag with it. The fix is to enforce the invariant server-side, at the step that depends on it.
Practise it
Every lab in the Business logic flaw category drills exactly this. Start at Apprentice and work up.