In this video, we will see how we can bypass rate limit and perform brute force attack in a login endpoint in graphql.
.
.
Introspection Query: https://github.com/medusa0xf/GraphQL-...
Tool used in this video: https://github.com/medusa0xf/GraphQL-...
PortSwigger Lab: https://portswigger.net/web-security/...
.
.
Blogs: / medusa0xf
.
.
.
Social media:
Twitter: / medusa_0xf
.
.
.
Discord: / discord
.
.
Music from #InAudio: https://inaudio.org/
Synthetic Pleasures
.
Like and Subscribe :)
.
.
.
#api #owasp #portswigger #bugbounty #bola #postman #pentesting #api #hack #bola #tryhackme #hackerone #apihacking #computerscience #javascript #python #postman #ctf #bughunting #pentesting #hacking #hackingtools #burpsuite #portswigger #ethicalhacking #OAuth #webhacking #programming #websecurity #technology #practical #artificialintelligence #web #recon #bypass