About GraphQL Exploitation
by gayass - Tuesday March 19, 2024 at 04:48 AM
#1
So, i'm trying to find a way to make my targets API show me more information about its GraphQL configs and stuff, but introspection is off, so my job became a little more difficult, so i wanted help from people who know more about the topic. Any suggestion is valid to me at this point rlly <3

Thank you in advance.
Reply
#2
(Mar 19, 2024, 04:48 AM)gayass Wrote: So, i'm trying to find a way to make my targets API show me more information about its GraphQL configs and stuff, but introspection is off, so my job became a little more difficult, so i wanted help from people who know more about the topic. Any suggestion is valid to me at this point rlly <3

Thank you in advance.

I am no expert myself and I started learning about hacking GraphQL recently, I think you can try some tricks here
https://portswigger.net/web-security/gra...n-defenses
also
https://book.hacktricks.xyz/network-serv...rospection

I hope this helps and happy hacking!.
Reply
#3
(Mar 19, 2024, 05:45 AM)leetone Wrote:
(Mar 19, 2024, 04:48 AM)gayass Wrote: So, i'm trying to find a way to make my targets API show me more information about its GraphQL configs and stuff, but introspection is off, so my job became a little more difficult, so i wanted help from people who know more about the topic. Any suggestion is valid to me at this point rlly <3

Thank you in advance.

I am no expert myself and I started learning about hacking GraphQL recently, I think you can try some tricks here
https://portswigger.net/web-security/gra...n-defenses
also
https://book.hacktricks.xyz/network-serv...rospection

I hope this helps and happy hacking!.

tyy! i'll have a look Big Grin
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Cardable Giftcard Websites AKASHIC 10 305 4 hours ago
Last Post: fokfdo223
  Bypassing Modern AV (Metasploit Method) godco99 3 250 4 hours ago
Last Post: kosele6846
  Acunetix 23.7 lolol 37 7,193 Apr 29, 2026, 09:37 AM
Last Post: Usercomplex
  [FREE] Database Searcher Telegram odanbtw 1,004 80,432 Apr 24, 2026, 12:13 PM
Last Post: FAKE_NBOBN00
  ✅ Top 10 Google Dorks For SQL Injections NextSoftGroup 9 223 Apr 24, 2026, 02:54 AM
Last Post: elliotalderson4

Forum Jump:


 Users browsing this forum: 1 Guest(s)