Nohé Hinniger-Foray

Full-Stack R&D Engineer @ Escape 💚 Computer science enthusiast. I love to craft new technologies, tools & applications. Open-sourcerer. 🧙‍♂️ ENSEEIHT Engineer My GitHub -> https://github.com/nohehf

Nohé Hinniger-Foray — Last Publications

Methodology: How we discovered over 2k high-impact vulnerabilities in apps built with vibe coding platforms
Research

Methodology: How we discovered over 2k high-impact vulnerabilities in apps built with vibe coding platforms

Hey there, With Halloween around the corner, what’s scarier for organizations than vulnerabilities in their web applications? And it's even scarier when the development of these applications is in the hands of users not familiar with security practices. This year, the Escape research team has focused on
Nohé Hinniger-Foray
Gwendal Mognier
Alexandra Charikova
Nohé Hinniger-Foray, Gwendal Mognier, Alexandra Charikova
10 min read
Limitations of current automatic specification generation tools
API Security

Limitations of current automatic specification generation tools

Have you ever wondered how automatic specification generation can streamline API security scanning? By significantly reducing the manual effort involved in creating and maintaining API specifications, automated tools offer clear benefits in terms of scan accuracy and setup time. Yet, many existing tools on the market have notable limitations. Understanding
Nohé Hinniger-Foray
Louis Betzer
Nohé Hinniger-Foray, Louis Betzer
5 min read
API Catalog & API Portal: A handbook of everything you should know
API

API Catalog & API Portal: A handbook of everything you should know

Discover the importance of API catalogs, their differences from API portals & gateways, and how to ensure optimal API management and security.
Nohé Hinniger-Foray
Nohé Hinniger-Foray
9 min read
GraphQL Wordlist: Free Open Source for Penetration Testing
GraphQL

GraphQL Wordlist: Free Open Source for Penetration Testing

In cybersecurity, the old saying that the "best defense is a good offense" rings true. This philosophy is reflected in the approach we call offensive security. It involves actively seeking out system vulnerabilities to fix them before they can be exploited. It's about taking the initiative,
Nohé Hinniger-Foray
Nohé Hinniger-Foray
5 min read
Goctopus: Open Source GraphQL Discovery & Fingerprinting
GraphQL

Goctopus: Open Source GraphQL Discovery & Fingerprinting

In the fast-evolving domain of APIs, GraphQL has emerged as a powerful, data-oriented language. As its adoption soars, so does the need for robust tools to discover and fingerprint these APIs. Enter Goctopus, a Golang-based solution we developed at Escape to provide comprehensive, fast, and interoperable endpoint discovery and fingerprinting
Nohé Hinniger-Foray
Nohé Hinniger-Foray
7 min read
Find & Fix GraphQL API Security Issues with Postman
Postman

Find & Fix GraphQL API Security Issues with Postman

Improve the security of your GraphQL API with Escape and Postman Are you tired of dealing with pesky API vulnerabilities? Want to take your GraphQL game to the next level? Introducing the perfect combo for GraphQL success - Escape and Postman. Escape is a tool that helps developers automatically and
Nohé Hinniger-Foray
Nohé Hinniger-Foray
3 min read
How to Use GraphQL with Postman: A Complete Guide
Postman

How to Use GraphQL with Postman: A Complete Guide

If you're building an API, you need tools to query it. Postman is the go-to tool for querying APIs, whether using the Postman GraphQL client or the Postman HTTP request interface. It allows you to create and send requests to your endpoints and so much more. Postman has
Nohé Hinniger-Foray
Nohé Hinniger-Foray
5 min read
GraphQL Postman Collection: Generate Instantly with GraphMan
Announcement

GraphQL Postman Collection: Generate Instantly with GraphMan

While querying, developing, and testing your GraphQL APIs with postman is easy and convenient, it has a big caveat: if you want to cover an endpoint with all its queries and mutations entirely, it will take you hours and repetitive steps to create every request, and you'll almost
Nohé Hinniger-Foray
Nohé Hinniger-Foray
3 min read