Sitemap
InfoSec Write-ups

A collection of write-ups from the best hackers in the world on topics ranging from bug bounties and CTFs to vulnhub machines, hardware challenges and real life encounters. Subscribe to our weekly newsletter for the coolest infosec updates: https://weekly.infosecwriteups.com/

Infosec
Hacking
Bug Bounty
Bug Bounty Tips
Cybersecurity

Business Logic Flaw That No One Knows About !

3 min readAug 6, 2025

--

For Non-Members : FREE LINK

जय श्री राम 🚩 Hackers,
In this writeup, I’m sharing one of the most overlooked and dangerous logic flaws I’ve encountered on a real-world car marketplace.

What I Found 🕵️

While testing a car marketplace platform, I discovered a business logic flaw that allowed me to manipulate subscriber counts endlessly — all without any hacking tools or advanced exploits.

On platforms where credibility = trust = sales, inflating followers could lead to financial scams, phishing attacks, and massive trust violations.

Theory Part : Business Logic Flaw

Press enter or click to view image in full size

A business logic flaw happens when an application works as intended — but the intent itself is flawed.

In this case, the app allowed users to subscribe (follow) others — but when the subscribing user deleted their account the server never removed that subscriber(follower)

Steps to Replicate

  1. Create two accounts On Two Different Browsers
    i) Account A (Main Profile) : Brave Browser
    ii) Account B ( Exploiting Profile ) Chrome Browser
  2. Log in as Account B and subscribe to Account A.

--

--

InfoSec Write-ups
InfoSec Write-ups

Published in InfoSec Write-ups

A collection of write-ups from the best hackers in the world on topics ranging from bug bounties and CTFs to vulnhub machines, hardware challenges and real life encounters. Subscribe to our weekly newsletter for the coolest infosec updates: https://weekly.infosecwriteups.com/