Главная
Study mode:
on
1
Intro
2
Schema
3
Mutations
4
Just GraphQL things
5
Introspection
6
Field Suggestions
7
Query Batching
8
Query Aliasing
9
Circular Queries
10
Operation Name Tampering
11
Field Duplication
12
Summary
13
About the Vulnerability
14
About the Exploit
15
Like DVWA, but for GraphQL
Description:
Explore GraphQL security in this NorthSec conference talk. Gain insights into attacking and defending GraphQL APIs, a REST alternative. Learn GraphQL basics, attack vectors, and defense strategies. Discover the Damn Vulnerable GraphQL Application (DVGA) for safe testing. Dive into topics like introspection, query batching, circular queries, and field duplication. Understand the challenges of securing new technologies and the importance of balancing adoption with security. Benefit from the speaker's extensive experience in Fintech and cybersecurity as you prepare for GraphQL's increasing presence in corporate networks.

Damn GraphQL - Attacking and Defending APIs

NorthSec
Add to list
0:00 / 0:00