Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Examining Access Control Vulnerabilities in GraphQL - A Feeld Case Study

DEFCONConference via YouTube

Overview

Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Explore the critical importance of implementing robust access controls in GraphQL and REST APIs through a comprehensive security analysis of real-world vulnerabilities. Examine how the lack of proper access control mechanisms in GraphQL, despite its flexibility in allowing clients to request specific data, can lead to severe security breaches and sensitive data exposure. Analyze the Feeld dating app as a detailed case study, investigating how inadequate access controls in both GraphQL and REST endpoints resulted in the exposure of users' personal information, including private photos, videos, and confidential messages. Learn to identify common access control vulnerabilities found in GraphQL and REST API implementations, understand the real-world impact of these security lapses on user privacy and data protection, and discover effective remediation strategies to prevent similar breaches. Gain practical insights into conducting thorough security reviews of API endpoints and implementing comprehensive access control measures to protect sensitive user data in modern web applications.

Syllabus

DEF CON 33 - Examining Access Control Vulnerabilities in GraphQL: A Feeld Case Study - Bogdan Tiron

Taught by

DEFCONConference

Reviews

Start your review of Examining Access Control Vulnerabilities in GraphQL - A Feeld Case Study

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.