“Package Hijack Meets GraphQL Goldmine: How One Recon Session Paid for My Caffeine Addiction”
一位网络安全专家通过工具和技术手段发现并利用目标网站的GraphQL端点漏洞进行攻击的过程描述。 2025-8-14 05:27:33 Author: infosecwriteups.com(查看原文) 阅读量:13 收藏

Iski

Free link 🎈

Hey there!😁

Press enter or click to view image in full size

Image by AI

You know those mornings where you drink so much caffeine you start seeing JSON responses in your dreams? Yeah… that was me. I was just casually scrolling through HackerOne reports for inspiration when my laptop whispered, “Hey, what if we poke around their GraphQL endpoint?”

Now, any sane person would’ve ignored that voice. I didn’t. I was already 3 cups in and my brain was itching for trouble.

I started with massive recon — think subfinder, amass, httpx, and a bit of gau magic:

subfinder -d target.com | tee subs.txt
cat subs.txt | httpx -title -status-code -silent | tee live.txt
cat live.txt | gau --threads 50 | grep -i graphql | tee graphql_endpoints.txt

文章来源: https://infosecwriteups.com/package-hijack-meets-graphql-goldmine-how-one-recon-session-paid-for-my-caffeine-addiction-8db6274d0811?source=rss----7b722bfd1b8d--bug_bounty
如有侵权请联系:admin#unsafe.sh