webProeasy

Просто найди его

hackerlab

Task: Flask app with GraphQL API where hidden queries exist beyond what the UI exposes. Solution: discover /graphql endpoint from client JS, use introspection to enumerate schema, find hidden getFlag query, call it with isAdmin: true.

$ ls tags/ techniques/
graphql_introspectionschema_enumerationhidden_query_discovery

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups