The chain, step by step
Each step depends on the one before it. Break any link and the chain stops there.
-
1
Step 1 of 8
An API is discovered whose endpoints are documented in a public JavaScript bundle.
-
2
Step 2 of 8
A GraphQL introspection query or a verbose error message reveals the full schema.
-
3
Step 3 of 8
Object-level authorization is tested by substituting another user's identifier in the request.
-
4
Step 4 of 8
Records belonging to other users are returned, confirming broken access control.
-
5
Step 5 of 8
A mass-assignment test adds an unexpected admin field to an otherwise normal update request.
-
6
Step 6 of 8
The elevated privilege persists because the role is trusted from the request body.
-
7
Step 7 of 8
Excessive data exposure is exploited by removing client-side field filters the server relied on.
-
8
Step 8 of 8
Bulk extraction follows, with pagination or rate limits simply driven to completion.
Entries behind these steps
The vulnerabilities, techniques and malware that make each stage possible.