{"repo":"dolevf/graphql-cop","free":true,"listed":false,"github":"https://github.com/dolevf/graphql-cop","clone":"git clone https://github.com/dolevf/graphql-cop.git","description":"Security Auditor Utility for GraphQL APIs","language":"Python","stars":686,"topics":["security","penetration-testing","auditing","graphql","hacking","red-team","blue-team","hardening"],"license":"MIT","category":"security-tools","readme_excerpt":"GraphQL Cop - Security Audit Utility for GraphQL About GraphQL Cop is a small Python utility to run common security tests against GraphQL APIs. GraphQL Cop is perfect for running CI/CD checks in GraphQL. It is lightweight, and covers interesting security issues in GraphQL. GraphQL Cop allows you to reproduce the findings by providing cURL commands upon any identified vulnerabilities. Requirements - Python3 - Requests Library Detections - Alias Overloading (DoS) - Batch Queries (DoS) - GET based Queries (CSRF) - POST based Queries using urlencoded payloads (CSRF) - GraphQL Tracing / Debug Modes (Info Leak) - Field Duplication (DoS) - Field Suggestions (Info Leak) - GraphiQL (Info Leak) - Introspection (Info Leak) - Directives Overloading (DoS) - Circular Query using Introspection (DoS) - Mutation support over GET methods (CSRF) Installation Below commands should be executed to install dependencies. First command creates a virtual environment in the directory specified by path/to/venv . Second command activates the virtual environment. Final command installs all the Python packages listed in the requirements.txt. Usage Test a website Exclude a specific test Test a website, dump to a parse-able JSON output, cURL reproduction command Test a website through a proxy (e.g. Burp Suite listening on 127.0.0.1:8080) with custom headers (e.g. Authorization): Docker Setup and Usage Prerequisites - Docker installed on your machine. Building the Docker Image 1. Clone the repository: 2. Buil","default_branch":null,"files":null,"tree":[],"storefront":"/r/dolevf","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/dolevf/graphql-cop/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}