Business Logic Abuse Wikipedia Article
There’s an article on wikipedia on business logic abuse. I’ve heard differing views on Wikipedia – some say it is a super handy reference while others think that encyclopedia articles written by the masses are unreliable at best.
The thing that’s great about wikipedia is that it lets lots of people contribute to crafting a comprehensive article. So – if you have thoughts on how business logic abuse should be defined, or examples, or references, I’d encourage you to contribute your part.
3 Comments »
Leave a Reply
-
Archives
- May 2012 (5)
- April 2012 (7)
- March 2012 (13)
- February 2012 (6)
- January 2012 (4)
- December 2011 (7)
- November 2011 (8)
- October 2011 (9)
- September 2011 (5)
- August 2011 (7)
- July 2011 (7)
- June 2011 (6)
-
Categories
- behavior analysis
- business logic abuse
- Business Logic Flaw
- Business Process Abuse
- Compliance
- Cost of fraud
- Data Loss
- Detection
- education
- Fraud
- Gaming
- General
- information security
- Investigation
- Man-in-the-Browser
- Online Fraud
- Payment
- Phishing
- predictive analytics
- Prevention
- risk management
- Social engineering
- Social Networks
- Trust
- Uncategorized
- web logic abuse
- Zeus
-
RSS
Entries RSS
Comments RSS


I recently picked up a 1976 book about Computer Crime. Written by a Joe Friday sort of character, it shows that most of the nonsense we’re dealing with today is not at all new. From physical attacks on computers, stealing files from timesharing computers, privacy issues, and the use of computers to support fraudulent activities, it’s enjoyable and enlightening. See
Crime By Computer (Donn B. Parker)
Agree – the internet is just another means to commit crimes.
Your comment made me think of other old crimes, especially the “con”. Look up “confidence game” (http://en.wikipedia.org/wiki/Confidence_trick) and you find similar terms used in describing “business logic abuse” (exploit weaknesses, vulnerability, using legitimate transactions, social engineering, etc). Is the con just attacking the legitimate human logic?
[...] and business logic flaws) to commit online fraud. It’s getting a lot of recognition, from Wikipedia articles (as highlighted in a recent post) to Black Hat presentations like the one from Jeremiah Grossman at [...]