Skip to Main Content (Press Enter)
Black Hat GraphQL by Nick Aleks and Dolev Farhi
Add Black Hat GraphQL to bookshelf
Add to Bookshelf

Black Hat GraphQL

Best Seller
Black Hat GraphQL by Nick Aleks and Dolev Farhi
Paperback $59.99
May 23, 2023 | ISBN 9781718502840

Buy from Other Retailers:

See All Formats (1) +
  • $59.99

    May 23, 2023 | ISBN 9781718502840

    Buy from Other Retailers:

  • May 23, 2023 | ISBN 9781718502857

    Buy from Other Retailers:

Product Details

Praise

Black Hat GraphQL is the best resource for anyone looking to test GraphQL for vulnerabilities. Not only did Aleks and Farhi write the book, but they also created the vulnerable application used in the books labs and created a suite of tools specially designed for analyzing weaknesses within GraphQL APIs. This is a must-read book for those in API security.”
—Corey Ball, author of Hacking APIs
 
“This book brought me from zero to ‘incredibly dangerous’ in ten chapters. The authors break down complex topics, making them easy to understand, as well as outlining pros and cons of each feature, tool, and tactic. The book also has quite a bit of foreshadowing, mentioning how certain parts of GraphQL work, and how they will be exploited later. The authors share not only several hands-on labs, but several tools they created themselves and open-sourced for all to use. If you are going to be PenTesting GraphQL systems, or are charged with protecting such a system, this book is a must-have.”
—Tanya Janca, founder of We Hack Purple
 
“With the increasing number of web platforms built on top of GraphQL, this book is an essential resource for all security practitioners. By covering both the basics and advanced topics, Nick and Dolev have created the ultimate guide to hacking GraphQL.”
—Luca Carettoni, Doyensec
 
“Knowing how to secure GraphQL is often the first question most users have after they have that “ah ha!” moment about how cool it is. While Apollo and others have written a lot of great documentation on best security practices, Black Hat GraphQL is the most comprehensive look from the other side. This is not just a book for red teamers or penetration testers. Any GraphQL developer will learn a lot here.”
—Tad Whitaker, Apollo GraphQL
 
“I study my way up in cybersecurity, in part, through books. While many of the books I use don’t actually bring something new to the table, Black Hat GraphQL is definitely an exception. My copy, believe it or not, is oversaturated with highlights. And that probably says it all.” 
—Cristi Vlad, @CristiVlad25, cybersecurity researcher

Table Of Contents

Foreword
Acknowledgments
Introduction
Chapter 1: A Primer on GraphQL
Chapter 2: Setting Up a GraphQL Security Lab
Chapter 3: The GraphQL Attack Surface
Chapter 4: Reconnaissance
Chapter 5: Denial of Service
Chapter 6: Information Disclosure
Chapter 7: Authentication and Authorization Bypasses
Chapter 8: Injection
Chapter 9: Request Forgery and Hijacking
Chapter 10: Disclosed Vulnerabilities and Exploits
Appendix A: GraphQL API Testing Checklist
Appendix B: GraphQL Security
Resources
Index

Looking for More Great Reads?
21 Books You’ve Been Meaning to Read
Back to Top