Web application security software vendor and security-as-a-service provider NT Objectives today released a list of the top 10 business logic attack vectors out there. A business logic flaw, for example, would entail using a simple script to manipulate the results of an online poll, or a shopping cart app with logic errors that allow attackers to bypass authentication and not actually pay for items.
Dan Kuykendall, co-CEO and CTO of NT Objectives, says most Web application security tests can be automated, but testing for business logic flaws must be performed manually by a penetration test. He says his firm has witnessed several breaches that have used a business logic flaw to get hack an organization.
"I don't think there is enough awareness" of these flaws and attacks, Kuykendall says. "The accessibility of Web applications tends to be a little easier to monitor the traffic and to try to exploit them" via these flaws, he says.
NT Objectives' Top 10 Business Logic Attack Vectors report is available here for download. "Business logic flaws are difficult to identify and discover. These flaws are unique to each application and must be discovered by manual testing. This paper is intended as a starting point to assist penetration testers with looking for these flaws as a part of their security reviews," according to NT Objectives' report.
Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.