Skip to content

Testing Business Logic

The weaknesses no scanner finds: legitimate requests in an illegitimate order.

Editorial team 2 min read

Business logic flaws are made of valid requests that the application should not have accepted together. Scanners cannot find them, because every individual request looks correct.

The questions that find them

What does the system assume about order? Can a step be skipped, repeated, or performed after the fact — confirming an order after cancellation, applying a discount after payment, uploading evidence after approval?

What does it assume about quantity? Negative amounts, zero, enormous values, fractional currency, and the same voucher used in two sessions at once.

What does it assume about state it does not own? Prices, totals and entitlements calculated on the client and trusted by the server are the oldest version of this problem and still common in checkout flows.

What happens concurrently? Race conditions turn one-use into many-use: two simultaneous withdrawals against the same balance, two redemptions of one code. Testing this needs parallel requests, not a sequence.

How to prepare

You cannot test logic you do not understand. Read the documentation, talk to whoever specified the feature, and write down the rules in plain sentences: "a refund cannot exceed the amount paid", "a free account may create three projects". Each sentence is a test.

Why it matters

These are the findings that cost money directly, and the ones most likely to be already in use by somebody who found them by accident.

More in Cyber security

All Cyber security guides →
Cyber security Guide · 2 min

What a Penetration Test Is, and Is Not

A penetration test is a time-boxed, authorised attempt to reach a defined objective — not a full inventory of every weakness you have.

Cyber security 2 min read 25 May 2025

Cyber security Guide · 2 min

Rules of Engagement and Authorisation

What to agree before any testing starts: scope, timing, data handling, escalation and the single document that makes the work lawful.

Cyber security 2 min read 24 May 2025

Cyber security Guide · 2 min

Writing a Finding People Will Fix

Severity, evidence, reproduction, impact in business terms, and a fix the team can actually make.

Cyber security 2 min read 23 May 2025

Cyber security Guide · 2 min

Vulnerability Scanning Done Properly

Credentialed scans, asset coverage, tuning out noise, and why scan counts are a bad metric.

Cyber security 2 min read 22 May 2025