Hintru ENES ← All labs
✎

Improve lab

Improved version of Breach - WebVerse (GraphQL)

You are creating a new version of this lab. The original stays untouched. Your version will be signed by a cryptographic key generated in your browser β€” no email, no password. If you clear browser data without exporting your identity, you lose authorship over your contributions.

You do not have a signing identity yet in this browser.
1
Identify the GraphQL Endpoint and Initial Query Structure
β–Ύ
πŸ’‘ Hint 1 β€” directional

Directional nudge β€” point at where to look without naming the technique.

🎯 Hint 2 β€” technique

Reveal the vulnerability class or technique without the exact payload.

πŸ”‘ Hint 3 β€” near solution

Near-solution: specific approach or command without the final flag.

2
Run GraphQL Introspection to Map the Schema
β–Ύ
πŸ’‘ Hint 1 β€” directional

Directional nudge β€” point at where to look without naming the technique.

🎯 Hint 2 β€” technique

Reveal the vulnerability class or technique without the exact payload.

πŸ”‘ Hint 3 β€” near solution

Near-solution: specific approach or command without the final flag.

3
Attempt to Query the Flag Field Without Arguments
β–Ύ
πŸ’‘ Hint 1 β€” directional

Directional nudge β€” point at where to look without naming the technique.

🎯 Hint 2 β€” technique

Reveal the vulnerability class or technique without the exact payload.

πŸ”‘ Hint 3 β€” near solution

Near-solution: specific approach or command without the final flag.

4
Pass an Argument to Reach the Restricted Field
β–Ύ
πŸ’‘ Hint 1 β€” directional

Directional nudge β€” point at where to look without naming the technique.

🎯 Hint 2 β€” technique

Reveal the vulnerability class or technique without the exact payload.

πŸ”‘ Hint 3 β€” near solution

Near-solution: specific approach or command without the final flag.