Skip to content

Some writeups of Black Hat GraphQL & Hacking APIs & Bug Bounty

Notifications You must be signed in to change notification settings

Monles/GraphQL-n-API-Bug-Bounty

Repository files navigation

Inspiring Quotes

"The best way to learn about hacking is by getting your hands dirty."

Black Hat GraphQL

"Hacking is not always about finding a single vulnerability but combining several weaknesses of an application into something critical."

Bug Bounty Bootcamp

Intro

Bug bounty programs often fall somewhere on the spectrum between black box and gray box testing (Hacking APIs, 2022).

Bug bounty programs offer a structured yet flexible testing environment. Hunters have enough information to guide their efforts efficiently (gray box elements) while still working from an external perspective without full access to the internal workings of the application (black box elements).

Setup of Labs

Please follow the instructions in INSTALL.md.

Practice with PortSwigger

  • There are many labs for you to practice web application security.
  • After creating an account / logging in, you can start practice the labs in PortSwigger.


References

About

Some writeups of Black Hat GraphQL & Hacking APIs & Bug Bounty

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published