Gain a Splash of New Skills - Coursera+ Annual Nearly 45% Off
35% Off Finance Skills That Get You Hired - Code CFI35
Overview
Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Explore GraphQL exploitation techniques focusing on secondary context attacks and business logic vulnerabilities in this 33-minute OWASP Foundation presentation. Dive into offensive security strategies discovered during real-world assessments, where GraphQL serves as a jumping-off point to access impactful API endpoints. Learn how these exploits can lead to significant security impacts including unauthorized data access, account modification capabilities, cross-tenancy failures, and Server-Side Request Forgery (SSRF). This offensively focused talk presents fresh material on GraphQL security vulnerabilities without rehashing existing exploitation discussions, making it essential viewing for security professionals interested in advanced GraphQL attack vectors.
Syllabus
GraphQL Exploitation: Secondary Context Attacks and Business Logic - Willis Vandevanter
Taught by
OWASP Foundation