🕵️
HowToHunt
search
⌘Ctrlk
🕵️
HowToHunt
  • HowToHunt.md
    • Hidden API Functionality Exposure
    • Reverse Engineer an API
    • Account Takeover Methodology
    • Application Level DoS Methods
    • 2FA Bypasses
    • OTP Bypass
    • Account Ban Bypass
    • Broken-Link Hijacking
    • Session Based Bugs
    • AEM
    • Drupal
    • Wordpress
    • Moodle
    • CORS
    • CORS Bypasses
    • CSRF
    • CSRF MindMap
    • CSRF Bypass
    • CVES
    • Web Application Pentesting Checklist
    • Web Checklist by Chintan Gurjar.pdfarrow-up-right
    • Web Checklist by Tushra Verma.pdfarrow-up-right
    • Mindmap by Rohit Gautamarrow-up-right
    • Mindmap by Cristian Corneaarrow-up-right
    • Web Page Code Review Tips
    • EXIF Geo Data Not Stripped
    • File Upload Bypass
    • Find Origin
    • GraphQL
    • HTTP_Desync
    • Host-Header
    • HTML-Injection
    • IDOR
    • JWT
    • JIRA
    • MFA Bypasses
    • 2FA-Bypass
    • Default Credential And Admin Panel
    • Docker
    • S3 Bucket
    • OAuth
    • OAuth Hunting
    • Find OpenRedirect Trick
    • Open Redirection Bypass
    • Parameter Pollution In Social Sharing Buttons
    • MindMap
    • Password Reset Token Leakage
    • Account_Takeover_By_Password_Reset_Functionality
    • Password_Reset_Flaws
    • Rate Limit Flaws
    • Rate-Limit Bypass
    • No Rate-Limit on Verify-PhoneNo
    • No Rate-limit on Invite User
    • No Rate-limit on Promo
    • No Rate-limit on Verify-email
    • No Rate-limit on forget-password
    • Race Condition
    • Github
    • Recon Workflow
    • Subdomain Enumeration
    • SQL Injection.md
    • SAML
    • SSRF
    • Blind SSRF
    • SSTI
    • Sign Up Bugs
    • Sign Up MindMap
    • Github Recon Method
    • Github-Dorks
    • Github Dorks All
    • Google Dorks
    • Shodan CVE Dorks
    • Version Leaks
    • Status_Code_Bypass Tips
    • 403 Bypass
    • Subdomain Takeover - Detail Method
    • Subdomain Takeover - Easy Method
    • Subs or Top level Domain
    • Tabnabbing
    • WAF Bypass Using Headers
    • Weak Password Policy
    • XSS
    • Bypass CSP
    • XSS Bypass
    • Automated XSS
    • Post Message Xss
    • XXE Methods
    • Billion Laugh Attack
gitbookPowered by GitBookgitbook
  1. GraphQL

GraphQL

hashtag
Videos

  • GraphQL Video - InsiderPhdarrow-up-right

  • REST in Peace: Abusing GraphQL to Attack Underlying Infrastructure - LevelUp 0x05arrow-up-right

hashtag
Blogs

  • Exploit GraphQL - Yeswehack Blogarrow-up-right

  • Hacking GraphQL - Part 1arrow-up-right Part 2arrow-up-right

  • That single GraphQL issue that you keep missingarrow-up-right by Doyensecarrow-up-right

  • Reverse engineer a GraphQL APIarrow-up-right

  • Exploiting GraphQLarrow-up-right by Assetnotearrow-up-right

  • GraphQL Resources Threadarrow-up-right by HolyBugxarrow-up-right

  • GraphQL Test Casesarrow-up-right

hashtag
Tools

  • GraphQL Voyagerarrow-up-right

  • GraphQL Cheatsheetarrow-up-right

  • AutoGraphQLarrow-up-right - Demo Videoarrow-up-right

  • graphw00farrow-up-right - GraphQL Server Engine Fingerprinting utility to learn more about what technology is behind a given GraphQL endpoint

  • InQL - Introspection GraphQL Scannerarrow-up-right - A security testing tool to facilitate GraphQL technology security auditing efforts

  • Graphicator is a GraphQL "scraper" / extractorarrow-up-right

hashtag
Labs

  • Damn-Vulnerable-GraphQL-Application - Githubarrow-up-right

PreviousFind Originchevron-leftNextHTTP_Desyncchevron-right

Last updated 2 years ago

Was this helpful?

  • Videos
  • Blogs
  • Tools
  • Labs

Was this helpful?