Case Study - Web Application Security Testing (Checkout Is the Target)

Discount code ADMIN90 was never meant to exist. We stacked it three times and checked out for Rp0.

ILLUSTRATION — WEB TEST COVERAGE (OWASP-BASED)
🔐
Auth & Session
Bypass, fixation, OTP
💉
Injection
XSS, SQLi, SSTI
🛒
Logic
Cart, voucher, race

Client Context

Top-5 e-commerce — web storefront + seller center + promo engine, 12M monthly users, 11.11 campaign in 5 weeks. Prior incident: voucher abuse Rp800M.

Challenge

Transactional logic (cart, voucher, payment callback) cannot be covered by scanners. Need automated web testing grounded in vulnerability patterns and security testing methodology (OWASP ASVS / Testing Guide), safe for staging with production-like data.

Scope - Snipeyes Web Application Security Testing

  • Crawl + authenticated journey maps (buyer, seller, admin): catalog → cart → checkout → payment → refund
  • Automated pattern packs: auth, access control, injection, business-logic abuse, file upload, payment callback tamper
  • Manual confirmation for every high/critical; evidence: request/response, video, CVSS + OWASP Risk Rating
  • Output: web security findings with replay steps developers can reproduce

Key Findings (redacted)

  • CRITICAL: Voucher stacking — ADMIN90 + free-shipping + cashback combinable → Rp0 checkout (logic flaw, reproduced 3x)
  • HIGH: Stored XSS in product Q&A → session hijack on seller admin
  • HIGH: Payment callback status=paid accepted without signature → order marked paid without transfer
  • 34 findings: 2 Critical, 5 High, 12 Medium, 15 Low

Outcome

  • Logic fixes deployed pre-11.11; callback now HMAC-signed + idempotency-keyed — zero voucher fraud during campaign
  • Retest 100% critical/high closed; regression pack reused every promo release
  • Findings mapped to OWASP ASVS 4.0 for ISO 27001 evidence

Relevance for you: If money moves through your web app — test the logic, not just the headers.