Attack chain 8 steps

API Abuse Chain

The whole chain in order — from the first touch to the objective — with the point at which each stage could have been stopped.

The chain, step by step

Each step depends on the one before it. Break any link and the chain stops there.

  1. 1

    Step 1 of 8

    An API is discovered whose endpoints are documented in a public JavaScript bundle.

  2. 2

    Step 2 of 8

    A GraphQL introspection query or a verbose error message reveals the full schema.

  3. 3

    Step 3 of 8

    Object-level authorization is tested by substituting another user's identifier in the request.

  4. 4

    Step 4 of 8

    Records belonging to other users are returned, confirming broken access control.

  5. 5

    Step 5 of 8

    A mass-assignment test adds an unexpected admin field to an otherwise normal update request.

  6. 6

    Step 6 of 8

    The elevated privilege persists because the role is trusted from the request body.

  7. 7

    Step 7 of 8

    Excessive data exposure is exploited by removing client-side field filters the server relied on.

  8. 8

    Step 8 of 8

    Bulk extraction follows, with pagination or rate limits simply driven to completion.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used