Web Application Manipulating the Checkout: A Masterclass in Business Logic Flaws
A Synack Red Team member discovered a cross-site scripting vulnerability in SAP Concur Open.
Synack unites the power of human expertise and AI technology to deliver continuous, trusted security testing at scale.
Synack combines agentic AI and human expertise to deliver pentesting solutions at scale.
Synack unites the power of human expertise and AI-driven technology to deliver continuous, trusted security testing at scale.
Synack unites the power of human expertise and AI-driven technology to deliver continuous, trusted security testing at scale.
Meet the experts who power Synack’s strategic security testing platform. Our Synack Red Team unites over 1,500 of the world’s most skilled and trusted security researchers, who work with patented technology to deliver best-in-class offensive security testing on a continuous basis.
Synack combines agentic AI and human expertise to deliver pentesting solutions at scale.
Explore educational guides and practical answers about penetration testing, AI security and vulnerability validation.
Browse all of our resources including videos, case studies, articles, podcasts and more.
Stay up to date on the latest industry trends, company news and research.
Hear from newsmakers, hackers, and big thinkers around the world share their cybersecurity insights.
A video series with candid perspectives on cybersecurity topics that matter.
Cut to the Chase. A live demo series that gets the point without wasting your time.
A series featuring technical vulnerability insights from the elite security researchers on the Synack Red Team (SRT).
Learn about cybersecurity industry terms and security testing solutions—what they do, why they’re important, and how they work.
Compare Synack side by side with other security testing platforms and vendors.
Join us for any in-person event, upcoming conference, or an online webinar.
Home > Archives by Tubagus Fahrudiansyah
Tubagus Fahrudiansyah is a security researcher on the Synack Red Team and a Synack Acropolis inductee, recognized for his work uncovering business logic vulnerabilities in production e-commerce systems. During a recent Synack engagement, he identified a critical desync between a payment gateway and its shopping cart that allowed attackers to finalize large orders for the price of a single low-cost item. He has also reported vulnerabilities through Google's Bug Hunters program.