This page indexes all the writeups for business logic bugs I’ve found: Application Logic Flaw Index.

  1. Business Logic Flaws and Yahoo Games
  2. How I got your phone number through Facebook
  3. How I hacked hundreds of companies through their helpdesk
  4. Price Tampering | Buying T-Shirts at 2 INR
  5. Bruteforce Protections Bypass
  6. Send a Email to me and get kicked out of Google Groups !!
  7. Google Security Misconfiguration Leads to Account Takeover!
  8. Story of YouTube’s Unfixable Ads Bypass
  9. A Weird Price Tampering Vulnerability
  10. Author spoofing in Google Colaboratory
  11. The invincible kid
  12. Simple & Sweet - Bypass email update restriction to change emails of team members
  13. Deleting other user's comments
  14. Why you shouldn’t share links on Facebook
  15. I Want that Cookie !!!
  16. Breaking the Competition (CTF hoster's Bug Bounty Write-up)
  17. Adding a malicious notebook to be treated like a trusted notebook in Google Colab
  18. Bypassing the patch for my previous Instagram bug
  19. How I acquired $XXX bounty by investing 99 cents
  20. How I am able to hijack your autosuggestions in Google Search
  21. Bypassing Scratch Cards On Google Pay
  22. Bypass HackerOne 2FA requirement and reporter blacklist
  23. Harvesting all private invites
  24. A possibility of Account Takeover in Medium
  25. Security teams Internal attachments can be exported via “Export as .zip” feature on HackerOne
  26. Payment bypass
  27. My First Swag Pack - A Logical Bug on Edmodo
  28. How I got paid premium plan for free on many popular websites
  29. Breaking Business Logic via Coupons
  30. How I broke into Google Issue Tracker
  31. How I Could Have Promoted Any Facebook Page For Free