Logic bugs require understanding how the app should work, then breaking that assumption.
example@target.com – may grant special privilegespremium_bought=0 to 1X-Forwarded-For, X-Real-IP“price”: 0.01 instead of real pricedig subdomain.target.com – look for NXDOMAIN, SERVFAIL, REFUSEDsubjack, can-i-take-over-xyz (GitHub), nuclei templates