نام کتاب
Black Hat GraphQL

Attacking Next Generation APIs

Nick Aleks, Dolev Farhi

Paperback314 Pages
PublisherNo Starch Press
Edition1
LanguageEnglish
Year2023
ISBN9781718502840
1K
A4424
انتخاب نوع چاپ:
جلد سخت
566,000ت
0
جلد نرم
506,000ت
0
طلق پاپکو و فنر
516,000ت
0
مجموع:
0تومان
کیفیت متن:اورجینال انتشارات
قطع:B5
رنگ صفحات:سیاه و سفید
پشتیبانی در روزهای تعطیل!
ارسال به سراسر کشور

#GraphQL

#APIs

#REST_APIs

#Attack

#Hijack

توضیحات

Written by hackers for hackers, this hands-on book teaches penetration testers how to identify vulnerabilities in apps that use GraphQL, a data query and manipulation language for APIs adopted by major companies like Facebook and GitHub.


Black Hat GraphQL is for anyone interested in learning how to break and protect GraphQL APIs with the aid of offensive security testing. Whether you’re a penetration tester, security analyst, or software engineer, you’ll learn how to attack GraphQL APIs, develop hardening procedures, build automated security testing into your development pipeline, and validate controls, all with no prior exposure to GraphQL required.


Following an introduction to core concepts, you’ll build your lab, explore the difference between GraphQL and REST APIs, run your first query, and learn how to create custom queries.


You’ll also learn how to:

  • Use data collection and target mapping to learn about targets
  • Defend APIs against denial-of-service attacks and exploit insecure configurations in GraphQL servers to gather information on hardened targets
  • Impersonate users and take admin-level actions on a remote server
  • Uncover injection-based vulnerabilities in servers, databases, and client browsers
  • Exploit cross-site and server-side request forgery vulnerabilities, as well as cross-site WebSocket hijacking, to force a server to request sensitive information on your behalf
  • Dissect vulnerability disclosure reports and review exploit code to reveal how vulnerabilities have impacted large companies


This comprehensive resource provides everything you need to defend GraphQL APIs and build secure applications. Think of it as your umbrella in a lightning storm.


Table of Contents

Chapter 1: A Primer on GraphQL

Chapter 2: Setting Up a GraphQL Security Lab

Chapter 3: The GraphQL Attack Surface

Chapter 4: Reconnaissance

Chapter 5: Denial of Service

Chapter 6: Information Disclosure

Chapter 7: Authentication and Authorization Bypasses

Chapter 8: Injection

Chapter 9: Request Forgery and Hijacking

Chapter 10: Disclosed Vulnerabilities and Exploits

Appendix A: GraphQL API Testing Checklist

Appendix B: GraphQL Security Resources


About the Authors

Dolev Farhi is a security engineer and author with extensive experience leading security engineering teams in complex environments and scale in the Fintech and cyber security industries. Currently, he is the Principal Security Engineer at Wealthsimple, building defenses for one of the fastest Fintech companies in North America. Dolev has previously worked for several security firms and provided training for official Linux certification tracks. He is one of the founders of DEFCON Toronto (DC416), a popular Toronto-based hacker group. In his spare time, he enjoys researching vulnerabilities in IoT devices, participating and building CTF challenges and contributing exploits to Exploit-DB.


Nick Aleks is a leader in Toronto's cybersecurity community and a distinguished and patented security engineer, speaker, and researcher. He is currently the Senior Director of Security at Wealthsimple, leads his own security firm, ASEC.IO, and is a Senior Advisory Board member for HackStudent, George Brown, and the University of Guelph’s Master of Cybersecurity and Threat Intelligence programs. A founder of DEFCON Toronto, he specializes in offensive security and penetration testing and has over 10 years of experience hacking everything from websites, safes, locks, cars, drones, and even smart buildings.

دیدگاه خود را بنویسید
نظرات کاربران (0 دیدگاه)
نظری وجود ندارد.
کتاب های مشابه
لینوکس
1,558
Black Hat Bash
534,000 تومان
هک و امنیت
497
Industrial Automation and Control System Security Principles
985,000 تومان
وب
963
Secure Web Application Development
679,000 تومان
هک و امنیت
918
Phishing and Communication Channels
413,000 تومان
هک و امنیت
1,543
Learning Malware Analysis
810,000 تومان
هک و امنیت
900
Keycloak – Identity and Access Management for Modern Applications
547,000 تومان
هک و امنیت
1,190
The Android Malware Handbook
526,000 تومان
هک و امنیت
897
Red Hat and IT Security
429,000 تومان
هک و امنیت
849
The Art of Intrusion
475,000 تومان
هک و امنیت
1,117
The Database Hacker's Handbook
902,000 تومان
قیمت
منصفانه
ارسال به
سراسر کشور
تضمین
کیفیت
پشتیبانی در
روزهای تعطیل
خرید امن
و آسان
آرشیو بزرگ
کتاب‌های تخصصی
هـر روز با بهتــرین و جــدیــدتـرین
کتاب های روز دنیا با ما همراه باشید
آدرس
پشتیبانی
مدیریت
ساعات پاسخگویی
درباره اسکای بوک
دسترسی های سریع
  • راهنمای خرید
  • راهنمای ارسال
  • سوالات متداول
  • قوانین و مقررات
  • وبلاگ
  • درباره ما
چاپ دیجیتال اسکای بوک. 2024-2022 ©