webProeasy
Просто найди его
hackerlab
Task: Flask app with GraphQL API where hidden queries exist beyond what the UI exposes. Solution: discover /graphql endpoint from client JS, use introspection to enumerate schema, find hidden getFlag query, call it with isAdmin: true.
$ ls tags/ techniques/
graphql_introspectionschema_enumerationhidden_query_discovery
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Космический терминал (Cosmic Terminal)— duckerz
- [web][Pro]Обычная страница— hackerlab
- [web][Pro]Секрет (Secret)— hackerlab
- [web][Pro]Документальный архив (Documentary Archive)— hackerlab
- [web][Pro]Lab 290 — PayLedger — GraphQL Broken Access Control— hackadvisor