GraphQL
Definition
Detection
Basics
Fingerprinting
Scan
Introspection enabled

Introspection disabled
Error Messages

JS Files

Scan endpoints
Wordlists
IDOR
IDORAdd extra field
Path Traversal
File Inclusion LFI / RFIMass Asignement - mutation
Mass AssignmentCSRF
Bypassing rate limits

Batching attack
SQL injection
SQL injection - Time based

Automated - Graphqlmap
NoSQL Injection
NoSQL injectionLDAP Injection
LDAP InjectionCommand injection
Command InjectionXSS
XSSHTML Injection
DoS throught batched queries
Wordlists
GraphQL Raider - Burp Extension
InQL
Burp Extension
CLI
Tools
Interesting Book
Support this Gitbook
Interesting Reports
Resources
Last updated


