Taking too long? Close loading screen.
November 5, 2024

Black Hat GraphQL: Attacking Next Generation APIs

Written by hackers for hackers, this hands-on book teaches penetration testers how to identify vulnerabilities in apps that use GraphQL, a data query and manipulation language for APIs adopted by major companies like Facebook and GitHub.

Black Hat GraphQL is for anyone interested in learning how to break and protect GraphQL APIs with the aid of offensive security testing. Whether you’re a penetration tester, security analyst, or software engineer, you’ll learn how to attack GraphQL APIs, develop hardening procedures, build automated security testing into your development pipeline, and validate controls, all with no prior exposure to GraphQL required.

Following an introduction to core concepts, you’ll build your lab, explore the difference between GraphQL and REST APIs, run your first query, and learn how to create custom queries.

You’ll also learn how to:

Use data collection and target mapping to learn about targets Defend APIs against denial-of-service attacks and exploit insecure configurations in GraphQL servers to gather information on hardened targetsImpersonate users and take admin-level actions on a remote serverUncover injection-based vulnerabilities in servers, databases, and client browsersExploit cross-site and server-side request forgery vulnerabilities, as well as cross-site WebSocket hijacking, to force a server to request sensitive information on your behalfDissect vulnerability disclosure reports and review exploit code to reveal how vulnerabilities have impacted large companies
This comprehensive resource provides everything you need to defend GraphQL APIs and build secure applications. Think of it as your umbrella in a lightning storm.
From the Publisher Copy of Black Hat GraphQL on black background with No Starch Press logoCopy of Black Hat GraphQL on black background with No Starch Press logo

Spread of Black Hat GraphQL on yellow backgroundSpread of Black Hat GraphQL on yellow background

Copy of Black Hat GraphQL on black backgroundCopy of Black Hat GraphQL on black background

Spread of Black Hat GraphQL on yellow backgroundSpread of Black Hat GraphQL on yellow background

'The best resource'

"The best resource for anyone looking to test GraphQL for vulnerabilities. Not only did Aleks and Farhi write the book, but they also created the vulnerable application used in the book's labs . . . This is a must-read book for those in API security."

—Corey Ball, author of Hacking APIs

'A must-have'

"This book brought me from zero to ‘incredibly dangerous’ in ten chapters. . . . If you are going to be PenTesting GraphQL systems, or are charged with protecting such a system, this book is a must-have."

—Tanya Janca, founder of We Hack Purple

'The ultimate guide'

“With the increasing number of web platforms built on top of GraphQL, this book is an essential resource for all security practitioners. By covering both the basics and advanced topics, Nick and Dolev have created the ultimate guide to hacking GraphQL.”

—Luca Carettoni, Doyensec

About the Authors

Dolev Farhi is a security engineer and author with extensive experience leading security engineering teams in complex environments and scale in the Fintech and cyber security industries. Currently, he is the Principal Security Engineer at Wealthsimple, building defenses for one of the fastest Fintech companies in North America. Dolev has previously worked for several security firms and provided training for official Linux certification tracks. He is one of the founders of DEFCON Toronto (DC416), a popular Toronto-based hacker group. In his spare time, he enjoys researching vulnerabilities in IoT devices, participating and building CTF challenges and contributing exploits to Exploit-DB.

Nick Aleks is a leader in Toronto's cybersecurity community and a distinguished and patented security engineer, speaker, and researcher. He is currently the Senior Director of Security at Wealthsimple, leads his own security firm, ASEC.IO, and is a Senior Advisory Board member for HackStudent, George Brown, and the University of Guelph’s Master of Cybersecurity and Threat Intelligence programs. A founder of DEFCON Toronto, he specializes in offensive security and penetration testing and has over 10 years of experience hacking everything from websites, safes, locks, cars, drones, and even smart buildings.

No Starch Press logo. A black circle with a white iron and a star in the centerNo Starch Press logo. A black circle with a white iron and a star in the center

About the Publisher

No Starch Press has published the finest in geek entertainment since 1994, creating both timely and timeless titles like Python Crash Course, Python for Kids, How Linux Works, and Hacking: The Art of Exploitation. An independent, San Francisco-based publishing company, No Starch Press focuses on a curated list of well-crafted books that make a difference. They publish on many topics, including computer programming, cybersecurity, operating systems, and LEGO. The titles have personality, the authors are passionate experts, and all the content goes through extensive editorial and technical reviews. Long known for its fun, fearless approach to technology, No Starch Press has earned wide support from STEM enthusiasts worldwide.


Publisher ‏ : ‎ No Starch Press (May 23, 2023)
Language ‏ : ‎ English
Paperback ‏ : ‎ 320 pages
ISBN-10 ‏ : ‎ 1718502842
ISBN-13 ‏ : ‎ 978-1718502840
Item Weight ‏ : ‎ 1.3 pounds
Dimensions ‏ : ‎ 7 x 0.73 x 9.25 inches
October 15, 2024

AI Content Marketing: Generate Leads, Engage Customers, and Boost ROI

Are you ready to unlock the power of AI for content creation?

With AI technology, you can generate compelling blog posts, captivating social media content, persuasive sales copy, and more – all while saving time and boosting your ROI.

In "AI Content Marketing: Learn How to Generate Leads, Engage Customers, and Boost Your Business ROI", you'll master the essentials of AI content creation, including:

Choosing the right AI writing tools for your needs (ChatGPT, Claude, Google Gemini, and more!)Partnering with AI for idea generation, compelling copy, and efficient editing.Tailoring content for different social media platforms.Using AI for content curation, repurposing, and visual content creation.Adapting your content with AI-powered insights to stay ahead of the curve with SEO.

This practical guide empowers you to create consistent, high-quality content with ease. Overcome writer's block, streamline your workflow, and achieve your marketing goals faster.

Whether you're a business owner, marketer, or content creator, "AI Content Marketing" is your blueprint for success in the AI-driven era. Get ready to transform your content strategy and save valuable time!