Hacking GraphQL endpoints with introspection, query, mutation, batching attacks
yeswehack.com | blog | #bug-bounty | #burp-suite | #fuzzing | #api-security | #graphql | #introspection
Summary
Practical guide to hacking GraphQL endpoints: abusing introspection, fuzzing when it is disabled, query and mutation vulnerabilities, batching attacks, plus tools like GraphQL Voyager and InQL.
- Published
- Collected
Skip to content