Table of Contents

Privilege, Transport, Logic

Privilege

Often logic, priv, auth bugs are blurred.

Testing user priv:

More Privilege

Autorize Burp plugin is pretty neat here.

Common Functions or Views

Insecure direct object references

IDORs are common place in bounties, and hard to catch with scanners.

Find any and all UIDs

Common Functions, Views, or Files:

Transport

Most security concerned sites will enable HTTPs. It's your job to ensure they've done it EVERYWHERE. Most of the time they miss something.

Examples:

ForceSSL

Business Logic Flaws

Logic flaws that are tricky, mostly manual: