Skip to main content
Evidence

What the chains actually looked like

Each of these reconstructs a chain from real B-52 engagements: what was done, what each step handed to the next, and what changed afterwards. Every step carries the weakness it maps to and the severity it was rated.

They are composites, and no customer is named on any of them. The engagement archive is usable for exactly this, anonymised to sector, industry and geography — so that is what you get, and the techniques are the part that transfers anyway.

The set

Five chains, five classes

Ordered by how much of the platform each one exercises rather than by date. The class column links to what that coverage class does in full.

EngagementSectorCoverage classChain
Tenant isolation on a SaaS platform Multi-tenant SaaS Web applications 4 steps
A valid user of one tenant reaching another tenant’s records, through an identifier the server resolved without asking who owned it.
Account takeover in a payments flow Payments APIs 4 steps
A login endpoint that answered differently for a known account than an unknown one, and what that difference was worth to somebody patient.
From an exposed secret to code execution Retail e-commerce External network 4 steps
A credential reachable without authenticating, still valid somewhere it should never have worked, and the execution that followed.
Internal foothold to domain admin Manufacturing Active Directory 5 steps
A service account recovered from where it was left, reused where it should not have been, and the path to privilege that opened.
A mobile binary and the API behind it Banking Mobile apps 5 steps
What a decompiled package said about the server behind it, and what the server accepted once somebody had read it.

Tenant isolation on a SaaS platform

Sector
Multi-tenant SaaS
Coverage class
Web applications
Chain
4 steps

A valid user of one tenant reaching another tenant’s records, through an identifier the server resolved without asking who owned it.

Account takeover in a payments flow

Sector
Payments
Coverage class
APIs
Chain
4 steps

A login endpoint that answered differently for a known account than an unknown one, and what that difference was worth to somebody patient.

From an exposed secret to code execution

Sector
Retail e-commerce
Coverage class
External network
Chain
4 steps

A credential reachable without authenticating, still valid somewhere it should never have worked, and the execution that followed.

Internal foothold to domain admin

Sector
Manufacturing
Coverage class
Active Directory
Chain
5 steps

A service account recovered from where it was left, reused where it should not have been, and the path to privilege that opened.

A mobile binary and the API behind it

Sector
Banking
Coverage class
Mobile apps
Chain
5 steps

What a decompiled package said about the server behind it, and what the server accepted once somebody had read it.

What is not here

The classes with no chain published yet

B-52 covers eleven coverage classes. 6 of them have no composite on this page yet, and naming them is more useful than letting the absence read as coverage:

Each of those is covered by the platform and has its own page. What it does not have is a chain written up here, which is a statement about this page rather than about the class.

Point it at something of yours

One application or one target, $500, and the report carries the same request, response and steps to reproduce that every chain on this page was written from.