Karim Rustom

Karim Rustom is the Offensive Security Lead at Escape, an ethical hacker and OSCP-certified security professional specializing in web app and API security. His work sits at the intersection of hands-on OffSec, vulnerability research, and AI.

Karim Rustom

Karim Rustom — Last Publications

Two Critical Vulnerabilities, One AI Pentester: How Cascade Found an Unauthenticated RCE and Walked Around the WAF
AI pentesting

Two Critical Vulnerabilities, One AI Pentester: How Cascade Found an Unauthenticated RCE and Walked Around the WAF

TL;DR We pointed Cascade, Escape's AI pentesting solution, at a single Spring + JSP customer portal. It came back with two findings that are typically difficult for traditional Dynamic Application Security Testing (DAST) scanners to detect: * Unauthenticated RCE via SpEL injection. A ref request parameter was dropped, unsanitized,
Karim Rustom
Karim Rustom
11 min read
GraphQL Pentesting: Thinking Outside the Box
Pentesting

GraphQL Pentesting: Thinking Outside the Box

The hardest part when pentesting any system is undoubtedly answering the question: 💡How should we think of that? What is meant is "how outside-the-box thinking works?", and "how is a pentester meant to think outside the box?". Although tackling this question might seem like a near
Karim Rustom
Karim Rustom
3 min read
How Gorillas's GraphQL API was leaking data from 10000 customers

How Gorillas's GraphQL API was leaking data from 10000 customers

German on-demand online grocery delivery company Gorillas took the industry by storm, guaranteeing delivery in under 10 minutes and gaining massive popularity throughout the pandemic. Founded in May 2020, Gorillas rapidly spread to dozens of European cities and America. After only three funding rounds, the last of which was in
Karim Rustom
Karim Rustom
3 min read
How to Secure GraphQL APIs in CI/CD: Best Practice
GraphQL

How to Secure GraphQL APIs in CI/CD: Best Practice

Secure your GraphQL APIs in CI/CD with Escape DAST that supports GraphQL natively.
Karim Rustom
Karim Rustom
4 min read
Escape joins the GraphQL Foundation to push for a more secure ecosystem

Escape joins the GraphQL Foundation to push for a more secure ecosystem

Alongside AWS, Microsoft, META, and PayPal, Escape has joined GraphQL Foundation to lend a hand to the GraphQL community in securing their APIs. Two years have passed since Escape members dedicated their work to providing all the necessary tools, support, and information to help the GraphQL community develop the most
Karim Rustom
Karim Rustom
1 min read
Pentesting GraphQL 101 
Part 3 - Exploitation

Pentesting GraphQL 101 Part 3 - Exploitation

This article is part of the series "Pentesting GraphQL 101". 1. Pentesting GraphQL 101 Part 1 - Discovery 2. Pentesting GraphQL 101 Part 2 - Interaction 3. Pentesting GraphQL 101 Part 3 - Exploitation Exploitation or finding vulnerabilities might not be the most crucial step in a typical
Karim Rustom
Karim Rustom
6 min read
GraphQL Pentesting 101: Part 2-Interaction Explained
Pentesting

GraphQL Pentesting 101: Part 2-Interaction Explained

A Pentester is usually expected to be a higher than average user in terms of interaction with an endpoint. For that reason, I decided to add an intermediary step between "Discovery" and "Exploiting" called "Interaction." This article is part of the series "Pentesting
Karim Rustom
Karim Rustom
5 min read
GraphQL Discovery: Pentesting GraphQL 101 Part 1
Pentesting

GraphQL Discovery: Pentesting GraphQL 101 Part 1

Recent statistics say that you have queried at least one GraphQL endpoint today. For me, as a Penetration tester, it is just a matter of concern, especially since high-quality Pentesting guides/articles are scarce online, which only signals that GraphQL security is still rudimentary. So I decided to start this
Karim Rustom
Karim Rustom
6 min read