I am in skill assessment of graphql. I searched everything. I found admin apikey, id and username. I don’t know what to do. I am out of ideas
1 Like
Me too. Can somebody lead us to answer? @positiveid
I got it, try to find vulnerability from last name and use that vulnerability to find flag
1 Like
Hey man I’m stuck here since 2 days, down in the rabbit hole
playing around this one:
{
x(x: “admin api”, x: “*****man”) {
x
x
x
x
}
}
I know here’s something but unable to exploit it.
No bro try to find sql injection vulnerability
yeah lastname thing, but couldnt exploit, i know maybe I would be doing something dumb and silly or ignoring something
Revisit to “injection” part of graphql module, it is very easy
I revisited, practiced again, and got the flag, thanks man!