{"repo":"dolevf/Black-Hat-GraphQL","free":true,"listed":false,"github":"https://github.com/dolevf/Black-Hat-GraphQL","clone":"git clone https://github.com/dolevf/Black-Hat-GraphQL.git","description":"The Black Hat GraphQL Book Repository","language":"HTML","stars":286,"topics":["book","graphql","hacking","nostarchpress","penetration-testing"],"license":null,"category":"security-tools","readme_excerpt":"Black Hat GraphQL Book files for Black Hat GraphQL . Black Hat GraphQL is for anyone interested in learning how to break and protect GraphQL APIs with the aid of offensive security testing. Whether you’re a penetration tester, security analyst, or software engineer, you’ll learn how to attack GraphQL APIs, develop hardening procedures, build automated security testing into your development pipeline, and validate controls, all with no prior exposure to GraphQL required. Buy the book from No Starch Press Enjoy! Errata Page 83 Listing 4-14: grep command should be corrected to: grep -Hnio \"graphiql\\ graphql-playground\" dvga-report/source/ Page 112: The sentence \" In DVGA, run the following query [...] \" should read: \" In Altair , run the following query [...] \". Page 177: The COOKIES variable value should read {\"session\":\"session-secret\"} Notes Due to changes in InQL, you may need to install the tool from the its V4 branch, latest version being 4.0.7","default_branch":null,"files":null,"tree":[],"storefront":"/r/dolevf","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/dolevf/Black-Hat-GraphQL/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}