Who Needs Admin When You Have GraphQL? Abusing Queries for Fun and Data
凌晨3点,作者通过GraphQL端点发现未受保护的接口,利用技术手段成功获取管理员权限。 2025-6-26 10:36:18 Author: infosecwriteups.com(查看原文) 阅读量:18 收藏

Iski

Free Link 🎈

Hey there!😁

image by Gemini Ai

Life lesson #231: If you can’t be admin by birth, be admin by enumeration. 😎

It was 3:12 AM, I was staring at my laptop with the same intensity people stare at their ex’s Instagram stories. I hadn’t slept, hadn’t eaten, and my only fuel was the leftover chai from 9PM. But then, I stumbled upon a GraphQL endpoint… and everything changed.

My recon process was in full swing:

subfinder -d target.com | httpx -title -tech-detect -mc 200 > live.txt
katana -list live.txt -jc -kf all -o jsendpoints.txt

While JS hunting, I spotted this spicy snippet:

fetch("https://api.target.com/graphql", { method: "POST", ... })

The endpoint was exposed. No auth headers. No JWT. No CSRF. Just wide open like a pani puri on the street.


文章来源: https://infosecwriteups.com/who-needs-admin-when-you-have-graphql-abusing-queries-for-fun-and-data-03456b01da34?source=rss----7b722bfd1b8d--bug_bounty
如有侵权请联系:admin#unsafe.sh