Русские видео

Сейчас в тренде

Иностранные видео




Если кнопки скачивания не загрузились НАЖМИТЕ ЗДЕСЬ или обновите страницу
Если возникают проблемы со скачиванием, пожалуйста напишите в поддержку по адресу внизу страницы.
Спасибо за использование сервиса ClipSaver.ru



Hunting for bugs in GraphQL APIs (Demo)

In this week's video I deliver on a promise! Last time I went over a ton of GraphQL theory, now we're going to turn that into practice! In this demo I show you how to write a basic query and mutation, then we look at introspection and recon on a GraphQL API, next I show you how to save time with GraphQL tools and finally, we put it all together and I demonstrate some real bugs! Did you know this episode was sponsored by Intigriti? Sign up with my link http://go.intigriti.com/katie I'm so pleased with everyone's positive response to the Intigriti sponsorship and I'm so pleased you folks are finding bugs and even finding your first bugs! Thank you for being awesome! Links - GraphQL Learn: https://graphql.org/learn/queries/ Introspection / general payloads: https://github.com/swisskyrepo/Payloa... GraphQL Voyager: https://github.com/APIs-guru/graphql-... InQL: https://github.com/doyensec/inql GraphQL Map: https://github.com/swisskyrepo/GraphQ... graphql-path-enum: https://gitlab.com/dee-see/graphql-pa... My video on Finding Bugs Using APIs:    • Finding Your First Bug: Finding Bugs ...   My video on the Top 10 API Bugs:    • Top 10 API Bugs (and Where to Find Them)   Farah's GraphQL Video:    • HACKING GraphQL FOR BEGINNERS + GIVEA...   My GraphQL Video:    • Finding Your Next Bug: GraphQL   A staff member with no permissions can edit Store Customer Email - $1,500: https://hackerone.com/reports/980511 Disclosure of `payment_transactions` for programs via GraphQL query - $2,500: https://hackerone.com/reports/707433 Hacker101 GraphQL levels: https://www.hackerone.com/blog/graphq... NoSQL Injection: http://www.petecorey.com/blog/2017/06... HackTricks - GraphQL: https://book.hacktricks.xyz/pentestin... GraphQL Security Overview: https://blog.doyensec.com/2018/05/17/... Social Media - Discord: https://insiderphd.dev/discord Patreon:   / insiderphd   Twitter:   / insiderphd   Patreon Shoutouts - David Kupratis Bruna Simonian Sean Doody Forrest Held Patreon Wardell Castles Gynvael Ram James Clee

Comments