Logs Don’t Lie: How a GraphQL Debug Endpoint Spilled the Entire Database 🗄️ | by Iski

letslearngraphql

Logs Don’t Lie: How a GraphQL Debug Endpoint Spilled the Entire Database 🗄️ | by Iski

🕵️‍♂️ Step 1 — Mass Recon & Weird GraphQL Subdomain. I was running my usual recon workflow: subfinder -d target.com -silent | httpx -silent -mc 200.

 

Read More