Nick Aleks and Dolev Farhi -- GraphQL Security episode artwork

EPISODE · Nov 1, 2022 · 43 MIN

Nick Aleks and Dolev Farhi -- GraphQL Security

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

GraphQL gives clients remarkable flexibility, but that same flexibility can expose authorization gaps, denial-of-service paths, and unexpected routes to sensitive data. Black Hat GraphQL authors Nick Aleks and Dolev Farhi join Chris and Robert to explain how GraphQL differs from SQL and REST, why its schema and query model change the attacker’s workflow, and which familiar web risks still apply. They explore introspection, field-level authorization, query depth and complexity, batching, injection, and direct attacks against GraphQL endpoints. The discussion moves from reconnaissance and exploitation to practical mitigations, including strong server-side controls, input validation, output encoding, and deliberate limits on what clients may request. Nick and Dolev also introduce the vulnerable applications and tooling behind their book and offer a path for practitioners to build hands-on GraphQL security skills.You are now listening to the Application Security Podcast brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Dolev Farhi and Nick Aleks:→ Dolev Farhi on LinkedIn→ Nick Aleks on LinkedIn→ Black Hat GraphQL→ Damn Vulnerable GraphQL ApplicationMentioned in this episode:→ Black Hat GraphQL (book)→ CrackQL→ Damn Vulnerable GraphQL Application→ Wealthsimple→ OWASP API Security Top 10Follow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Nick Aleks and Dolev Farhi: GraphQL Security04:44 Dolev’s security origin story07:01 Introducing Black Hat GraphQL07:51 What GraphQL is and where teams use it10:57 GraphQL compared with SQL13:19 The GraphQL threat landscape18:16 How familiar OWASP risks appear in GraphQL20:59 How attackers discover and reach GraphQL endpoints29:24 Mitigating authorization and denial-of-service risks34:14 Server-side controls, validation, and output encoding36:56 Why Nick and Dolev wrote the book40:00 Practical GraphQL security takeaways

Episode metadata supplied by the publisher feed · Published Nov 1, 2022

Embed this episode

GraphQL gives clients remarkable flexibility, but that same flexibility can expose authorization gaps, denial-of-service paths, and unexpected routes to sensitive data. Black Hat GraphQL authors Nick Aleks and Dolev Farhi join Chris and Robert to explain how GraphQL differs from SQL and REST, why its schema and query model change the attacker’s workflow, and which familiar web risks still apply. They explore introspection, field-level authorization, query depth and complexity, batching, injec...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Nick Aleks and Dolev Farhi -- GraphQL Security

0:00 43:40

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 43 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on November 1, 2022.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!