Burp Suite User Forum

Create new post

I don't understand business logic vulnerabilities image example in the web

wof | Last updated: Sep 30, 2024 01:58PM UTC

In the portswigger web-security section: https://portswigger.net/web-security/logic-flaws The following image is used to describe the business logic vulnerabilities https://portswigger.net/web-security/images/logic-flaws.jpg I understand that the first two attempts failed due to wrong password. What I don't understand is how the third attempt caused the combination of username and password to be correct?

Ben, PortSwigger Agent | Last updated: Oct 01, 2024 08:26AM UTC

Hi, The image itself is not supposed to be representative of the specifics of how an attack actually works, it is simply a bit of fun to give a flavour of the vulnerability being described.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.