Help needed Gpahql skill assessment [SOLVED]

I am in skill assessment of graphql. I searched everything. I found admin apikey, id and username. I don’t know what to do. I am out of ideas

1 Like

Me too. Can somebody lead us to answer? @positiveid

I got it, try to find vulnerability from last name and use that vulnerability to find flag

1 Like

Hey man I’m stuck here since 2 days, down in the rabbit hole

playing around this one:

{
x(x: “admin api”, x: “*****man”) {
x
x
x
x
}
}

I know here’s something but unable to exploit it.

No bro try to find sql injection vulnerability

yeah lastname thing, but couldnt exploit, i know maybe I would be doing something dumb and silly or ignoring something

Revisit to “injection” part of graphql module, it is very easy

I revisited, practiced again, and got the flag, thanks man!