Skip to main content
This page aggregates cross-platform resources to practice Business Logic Vulnerabilities: retired Hack The Box machines, PortSwigger Web Security Academy labs and TryHackMe rooms, plus curated resources (HackTricks, PortSwigger, etc.) and related skills. Coverage: 12 challenges across 1 platform — 12 PortSwigger. 0 with a Spanish writeup, 0 with a video writeup.

Where to start

Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.
  1. PortSwiggerBypassing access controls using email address parsing discrepancies (Apprentice) · 🇬🇧
  2. PortSwiggerExcessive trust in client-side controls (Apprentice) · 🇬🇧
  3. PortSwiggerFlawed enforcement of business rules (Apprentice) · 🇬🇧
  4. PortSwiggerHigh-level logic vulnerability (Apprentice) · 🇬🇧
  5. PortSwiggerInconsistent security controls (Apprentice) · 🇬🇧
  6. PortSwiggerAuthentication bypass via encryption oracle (Practitioner) · 🇬🇧

Curated resources

PortSwigger labs practicing Business Logic Vulnerabilities (12)


Back to the full glossary Last updated: 2026-08-17