GraphQL

29 posts

GraphQL Pentesting 101: Part 2-Interaction Explained
Pentesting

GraphQL Pentesting 101: Part 2-Interaction Explained

A Pentester is usually expected to be a higher than average user in terms of interaction with an endpoint. For that reason, I decided to add an intermediary step between "Discovery" and "Exploiting" called "Interaction." This article is part of the series "Pentesting
Karim Rustom
Karim Rustom
5 min read
How to Use GraphQL with Postman: A Complete Guide
Postman

How to Use GraphQL with Postman: A Complete Guide

If you're building an API, you need tools to query it. Postman is the go-to tool for querying APIs, whether using the Postman GraphQL client or the Postman HTTP request interface. It allows you to create and send requests to your endpoints and so much more. Postman has
Nohé Hinniger-Foray
Nohé Hinniger-Foray
5 min read
GraphQL Discovery: Pentesting GraphQL 101 Part 1
Pentesting

GraphQL Discovery: Pentesting GraphQL 101 Part 1

Recent statistics say that you have queried at least one GraphQL endpoint today. For me, as a Penetration tester, it is just a matter of concern, especially since high-quality Pentesting guides/articles are scarce online, which only signals that GraphQL security is still rudimentary. So I decided to start this
Karim Rustom
Karim Rustom
6 min read
GraphQL Postman Collection: Generate Instantly with GraphMan
Announcement

GraphQL Postman Collection: Generate Instantly with GraphMan

While querying, developing, and testing your GraphQL APIs with postman is easy and convenient, it has a big caveat: if you want to cover an endpoint with all its queries and mutations entirely, it will take you hours and repetitive steps to create every request, and you'll almost
Nohé Hinniger-Foray
Nohé Hinniger-Foray
3 min read
GraphQL Security: 9 Best Practices You Need to Know
AppSec

GraphQL Security: 9 Best Practices You Need to Know

GraphQL has no security by default. All doors are open for the most basic attacks. Read more to learn about the exact threats and some simple strategies you can implement to get your users' data under lock and key 🔐
Achraf Ait Sidi Hammou
Achraf Ait Sidi Hammou
8 min read