The Application Security Podcast cover image

Nick Aleks and Dolev Farhi -- GraphQL Security

The Application Security Podcast

00:00

How Do You Attack GraphQL Instances?

GraphQL can really be implemented anywhere within a company's infrastructure. A lot of the times they will implement a GraphQL API server at their gateway. Once you get access to that API endpoint and, you know, let's say there's no authentication or authorization behind it, you can immediately start to send a couple of queries to the actual API server. If you are attacking GraphQL, you'll most likely want to look for a couple of endpoints,. Now it's unlike REST APIs where you've got like a lot of different endpoints. When it comes to Graph Qls, you only have to deal with one API endpoint usually.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app