“Package Hijack Meets GraphQL Goldmine: How One Recon Session Paid for My Caffeine Addiction”
文章描述了一位网络安全爱好者在摄入大量咖啡因后,利用工具链(如subfinder、amass、httpx和gau)对目标域名进行网络资产测绘和GraphQL端点探测的过程。 2025-8-14 05:27:33 Author: infosecwriteups.com(查看原文) 阅读量:12 收藏

Iski

Free link 🎈

Hey there!😁

Press enter or click to view image in full size

Image by AI

You know those mornings where you drink so much caffeine you start seeing JSON responses in your dreams? Yeah… that was me. I was just casually scrolling through HackerOne reports for inspiration when my laptop whispered, “Hey, what if we poke around their GraphQL endpoint?”

Now, any sane person would’ve ignored that voice. I didn’t. I was already 3 cups in and my brain was itching for trouble.

I started with massive recon — think subfinder, amass, httpx, and a bit of gau magic:

subfinder -d target.com | tee subs.txt
cat subs.txt | httpx -title -status-code -silent | tee live.txt
cat live.txt | gau --threads 50 | grep -i graphql | tee graphql_endpoints.txt

文章来源: https://infosecwriteups.com/package-hijack-meets-graphql-goldmine-how-one-recon-session-paid-for-my-caffeine-addiction-8db6274d0811?source=rss----7b722bfd1b8d---4
如有侵权请联系:admin#unsafe.sh