Penetration Testing
search
⌘Ctrlk
Penetration Testing
  • Web
    • Reconnaissance
    • Open Source Intelligence
    • Misconfiguration
    • Identity Management
    • Broken Authentication
    • Broken Authorization
    • Session Management
    • Input Validation
    • Error Handling
    • Weak Cryptography
    • Business Logic
      • Logic Data Validation
      • Ability to Forge Requests
      • Integrity Checks
      • Process Timing
      • Race Conditions
      • Circumvention of Work Flows
      • Defenses Against Application Misuse
      • Upload of Unexpected File Types
      • Upload of Malicious Files
      • Payment Functionality
    • Client Side
    • API Attacks
  • Mobile
    • Mobile App Taxonomy
    • Mobile App Security Testing
    • General
    • Android
    • iOS
  • Cloud
    • Reconnaissance
    • SaaS
    • IaaS
    • Azure
    • AWS
    • GCP
    • IBM
    • Digital Ocean
    • Kubernetes
    • CI/CD
    • Active Directory
  • Network
    • Introduction
    • Intelligence Gathering
    • Vulnerability Analysis
    • Logical Vulnerabilities
    • Exploitation of Remote Services (User-Mode)
    • Exploitation of Remote Services (Kernel-Mode)
  • Wireless
    • Page 4
  • iot
    • Page 5
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Web

Business Logic

Logic Data Validationchevron-rightAbility to Forge Requestschevron-rightIntegrity Checkschevron-rightProcess Timingchevron-rightRace Conditionschevron-rightCircumvention of Work Flowschevron-rightDefenses Against Application Misusechevron-rightUpload of Unexpected File Typeschevron-rightUpload of Malicious Fileschevron-rightPayment Functionalitychevron-right
PreviousWeak Encryptionchevron-leftNextLogic Data Validationchevron-right

Last updated 2 years ago