Escape - The GraphQL Security Blog
  • Main website
  • Community
  • Open Source
  • GraphQL.Security
Try our GraphQL Security Platform now →
Karim Rustom

Karim Rustom

2 posts published

Pentesting GraphQL 101 
Part 2 - Interaction

Pentesting GraphQL 101 Part 2 - Interaction

A Pentester is usually expected to be a higher than average user in terms of interaction with an endpoint. For that reason, I decided to add an intermediary step between "Discovery" and "Exploiting" called "Interaction." Today's article contains three real-life examples that hopefully provide insight into the pentester mentality when

  • Karim Rustom
Karim Rustom Jul 29, 2022 • 4 min read
Pentesting GraphQL 101 
Part 1 - Discovery

Pentesting GraphQL 101 Part 1 - Discovery

Recent statistics say that you have queried at least one GraphQL endpoint today. For me, as a Penetration tester, it is just a matter of concern, especially since high-quality Pentesting guides/articles are scarce online, which only signals that GraphQL security is still rudimentary. So I decided to start this

  • Karim Rustom
Karim Rustom Jul 19, 2022 • 5 min read
Escape - The GraphQL Security Blog © 2022
  • Data & privacy
  • Contact
  • Contribute →
  • Company Website