{"repo":"dolevf/Damn-Vulnerable-GraphQL-Application","free":true,"listed":false,"github":"https://github.com/dolevf/Damn-Vulnerable-GraphQL-Application","clone":"git clone https://github.com/dolevf/Damn-Vulnerable-GraphQL-Application.git","description":"Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL Security.","language":"JavaScript","stars":1704,"topics":["vulnerability","graphql","security","penetration-testing","damn-vulnerable","damn-vulnerable-web-application","graphql-security","exploitation"],"license":"MIT","category":"security-tools","readme_excerpt":"Damn Vulnerable GraphQL Application Damn Vulnerable GraphQL Application is an intentionally vulnerable implementation of Facebook's GraphQL technology, to learn and practice GraphQL Security. Table of Contents About DVGA Operation Modes Scenarios Prerequisites Installation Installation - Docker Installation - Docker Registry Installation - Server Screenshots Maintainers Contributors Mentions Disclaimer License About DVGA Damn Vulnerable GraphQL is a deliberately weak and insecure implementation of GraphQL that provides a safe environment to attack a GraphQL application, allowing developers and IT professionals to test for vulnerabilities. DVGA Operation Support - Queries - Mutations - Subscriptions DVGA has numerous flaws, such as Injections, Code Executions, Bypasses, Denial of Service, and more. See the full list under the Scenarios section. A public Postman collection is also available to replay solutions to the challenges. You can import the collection by clicking on the Run in Postman button below. Operation Modes DVGA supports Beginner and Expert level game modes, which will change the exploitation difficulty. Scenarios Reconnaissance Discovering GraphQL Fingerprinting GraphQL Denial of Service Batch Query Attack Deep Recursion Query Attack Resource Intensive Query Attack Field Duplication Attack Aliases based Attack Information Disclosure GraphQL Introspection GraphiQL Interface GraphQL Field Suggestions Server Side Request Forgery Stack Trace Errors Code Execution OS ","default_branch":null,"files":null,"tree":[],"storefront":"/r/dolevf","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/dolevf/Damn-Vulnerable-GraphQL-Application/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}