
API Security Risks with OWASP - .NET 151
Adventures in .NET
00:00
The Risks of Unrestricted Resource Consumption in APIs
It's unrestricted resource consumption. So that the API is subject to a denial of service attack or what I see more and more often is lots of applications these days they're using GraphQL. With complexity, of course, always comes the risk that there is some abuse possible. And one thing I recently found in audit, for instance, was there was a GraphQL query where some really complex database logic was triggered by a GraphQL call. The application therefore set, it was using paging for the results and was setting a page size as part of the GraphQL query. We could find out that you could change the query and use a very, very large page size and that basically send a
Transcript
Play full episode