Case Study - Web Application Security Testing (Checkout Is the Target)
Discount code
ADMIN90was never meant to exist. We stacked it three times and checked out for Rp0.
Bypass, fixation, OTP
XSS, SQLi, SSTI
Cart, voucher, race
Client Context
Top-5 e-commerce — web storefront + seller center + promo engine, 12M monthly users, 11.11 campaign in 5 weeks. Prior incident: voucher abuse Rp800M.
Challenge
Transactional logic (cart, voucher, payment callback) cannot be covered by scanners. Need automated web testing grounded in vulnerability patterns and security testing methodology (OWASP ASVS / Testing Guide), safe for staging with production-like data.
Scope - Snipeyes Web Application Security Testing
- Crawl + authenticated journey maps (buyer, seller, admin): catalog → cart → checkout → payment → refund
- Automated pattern packs: auth, access control, injection, business-logic abuse, file upload, payment callback tamper
- Manual confirmation for every high/critical; evidence: request/response, video, CVSS + OWASP Risk Rating
- Output: web security findings with replay steps developers can reproduce
Key Findings (redacted)
- CRITICAL: Voucher stacking —
ADMIN90+ free-shipping + cashback combinable → Rp0 checkout (logic flaw, reproduced 3x) - HIGH: Stored XSS in product Q&A → session hijack on seller admin
- HIGH: Payment callback
status=paidaccepted without signature → order marked paid without transfer - 34 findings: 2 Critical, 5 High, 12 Medium, 15 Low
Outcome
- Logic fixes deployed pre-11.11; callback now HMAC-signed + idempotency-keyed — zero voucher fraud during campaign
- Retest 100% critical/high closed; regression pack reused every promo release
- Findings mapped to OWASP ASVS 4.0 for ISO 27001 evidence
Relevance for you: If money moves through your web app — test the logic, not just the headers.