Fr. 95.00

Black Hat GraphQL - Attacking Next Generation APIs

English · Paperback / Softback

Shipping usually within 4 to 7 working days

Description

Read more

Written by hackers for hackers, this hands-on book teaches penetration testers how to identify vulnerabilities in apps that use GraphQL, a data query and manipulation language for APIs adopted by major companies like Facebook and GitHub. Web applications are increasingly using the query language GraphQL to share data, but the security of these useful APIs is lagging behind. Authored by the developers of widely used GraphQL security-testing tools, Early chapters provide in-depth knowledge of GraphQL and its query language, as well as its potential security pitfalls. Readers will then be guided through setting up a hacking lab for targeting GraphQL applications using specialized GraphQL security tools. They will learn how to conduct offensive security tests against production GraphQL systems by gleaning information from GraphQL implementations during reconnaissance and probing them for vulnerabilities, like injections, information disclosure, and Denial of Service.

Product details

Authors Nick Aleks, Opheliar Chan, Dolev Farhi
Publisher No Starch Press
 
Languages English
Product format Paperback / Softback
Released 21.03.2023
 
EAN 9781718502840
ISBN 978-1-71850-284-0
No. of pages 320
Dimensions 178 mm x 235 mm x 19 mm
Subjects Natural sciences, medicine, IT, technology > IT, data processing > Data communication, networks

COMPUTERS / Software Development & Engineering / General, COMPUTERS / Programming / General, Computer programming / software engineering, Computer Programming / Software Development

Customer reviews

No reviews have been written for this item yet. Write the first review and be helpful to other users when they decide on a purchase.

Write a review

Thumbs up or thumbs down? Write your own review.

For messages to CeDe.ch please use the contact form.

The input fields marked * are obligatory

By submitting this form you agree to our data privacy statement.