Business Logic Errors

A collection of Business Logic Errors write-ups and report

🔴 Ethereum account balance manipulation

By using a smart contract to distribute ether over a set of wallets you can manipulate the account balance of your Coinbase account.

Url Type Bounty
https://hackerone.com/reports/300748 Account Manipulation $10000

🟡 Improperly implemented password recovery link functionality

User gets automatically logged in after clicking the password recovery link

Url Type Bounty
https://hackerone.com/reports/809 Improper Authentication $300

🔴 Account Takeover Vulnerability

Forgot Password functionality combind with Host Header attack

🟠 Logic flaw in the registration process to get more trial time.

By registering a new account with +1 in the email it would get another trail on the main email.

🟡 Adding more than maximum two team members in free trail

By registering a new account with +1 in the email it would get another trail on the main email.

🟡 Adding more than maximum two team members in free trail

By registering a new account with +1 in the email it would get another trail on the main email.

🔴 Bypassed Login & MFA Using a Race Condition + JWT Leak

What happens when you race 50+ login requests at once? Sometimes, magic.