{"repo":"dolevf/graphw00f","free":true,"listed":false,"github":"https://github.com/dolevf/graphw00f","clone":"git clone https://github.com/dolevf/graphw00f.git","description":"graphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology is behind a given GraphQL endpoint.","language":"Python","stars":889,"topics":["graphql","security","fingerprinting","enumeration","penetration-testing","information-gathering"],"license":"BSD-3-Clause","category":"security-tools","readme_excerpt":"Credits to Nick Aleks for the logo! graphw00f - GraphQL Server Fingerprinting Table of Contents How does it work? Detections GraphQL Threat Matrix Prerequisites Installation Configuration Example Usage Fingerprinting GraphQL Detecting & Fingerprinting GraphQL Support & Issues Resources How does it work? graphw00f (inspired by wafw00f) is the GraphQL fingerprinting tool for GQL endpoints, it sends a mix of benign and malformed queries to determine the GraphQL engine running behind the scenes. graphw00f will make use of the GraphQL Threat Matrix project to provide insight into what security defences each technology provides out of the box, and whether they are on or off by default. Specially crafted queries cause different GraphQL server implementations to respond uniquely to queries, mutations and subscriptions, this makes it trivial to fingerprint the backend engine and distinguish between the various GraphQL implementations. (CWE: CWE-200) graphw00f supports detecting and fingerprinting GraphQL servers that make use of either GET or POST-based querying. Detections graphw00f currently attempts to discover the following GraphQL engines: Graphene - Python Ariadne - Python Apollo - TypeScript graphql-go - Go gqlgen - Go WPGraphQL - PHP GraphQL API for Wordpress - PHP Gato GraphQL - PHP graphql-ruby - Ruby graphql-php - PHP Hasura - Haskell HyperGraphQL - Java graphql-java - Java Juniper - Rust Sangria - Scala Flutter - Dart Diana.jl - Julia Strawberry - Python Tartiflette - Pyth","default_branch":null,"files":null,"tree":[],"storefront":"/r/dolevf","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/dolevf/graphw00f/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}