Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Nick Aleks and Dolev Farhi -- GraphQL Security

44 min1 november 2022

Om avsnittet

GraphQL gives clients remarkable flexibility, but that same flexibility can expose authorization gaps, denial-of-service paths, and unexpected routes to sensitive data. Black Hat GraphQL authors Nick Aleks and Dolev Farhi join Chris and Robert to explain how GraphQL differs from SQL and REST, why its schema and query model change the attacker’s workflow, and which familiar web risks still apply. They explore introspection, field-level authorization, query depth and complexity, batching, injection, and direct attacks against GraphQL endpoints. The discussion moves from reconnaissance and exploitation to practical mitigations, including strong server-side controls, input validation, output encoding, and deliberate limits on what clients may request. Nick and Dolev also introduce the vulnerable applications and tooling behind their book and offer a path for practitioners to build hands-on GraphQL security skills.

You are now listening to the Application Security Podcast brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Dolev Farhi and Nick Aleks:
Dolev Farhi on LinkedIn
Nick Aleks on LinkedIn
Black Hat GraphQL
Damn Vulnerable GraphQL Application

Mentioned in this episode:
Black Hat GraphQL (book)
CrackQL
Damn Vulnerable GraphQL Application
Wealthsimple
OWASP API Security Top 10

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Meet Nick Aleks and Dolev Farhi: GraphQL Security
04:44 Dolev’s security origin story
07:01 Introducing Black Hat GraphQL
07:51 What GraphQL is and where teams use it
10:57 GraphQL compared with SQL
13:19 The GraphQL threat landscape
18:16 How familiar OWASP risks appear in GraphQL
20:59 How attackers discover and reach GraphQL endpoints
29:24 Mitigating authorization and denial-of-service risks
34:14 Server-side controls, validation, and output encoding
36:56 Why Nick and Dolev wrote the book
40:00 Practical GraphQL security takeaways

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.