ZA·005 Talk 2024
Attacking GraphQL: A guide for penetration testers
- Event
- BSides Cape Town
- Region
- South Africa
- Language
- EN
Abstract
Whats GraphQL? How do pwn it? And what do I write in my pentest report if I get this in a test? If these questions get your heart racing, fret not, this stalk is for you! GraphQL is at minimum, yet another API technology your company can get horribly wrong. The technology has grown considerably has an API interface technology in the last few years. With the growing interest, security engineering has been a keen focus for deployments because the technology is new, promises a lot (i.e. strict data typing, query batching and nesting, rapid adaptability etc.) and may not deliver the same impact in all environments or use cases.
Sources
- Watch the recording youtube.com
- Archived copy web.archive.org
- Where this entry came from bsidescapetown.co.za
Source of truth:
data/works/attacking-graphql-2024.yaml