Utilitaire Python léger pour l'audit de sécurité automatisé des API GraphQL. Détecte les erreurs de configuration, les fuites d'informations et les vulnérabilités de déni de service avec des commandes de reproduction cURL.
GraphQL Cop est un petit utilitaire Python pour exécuter des tests de sécurité courants contre les API GraphQL. GraphQL Cop est parfait pour effectuer des vérifications CI/CD dans GraphQL. Il est léger et couvre des problèmes de sécurité intéressants dans GraphQL.
GraphQL Cop vous permet de reproduire les résultats en fournissant des commandes cURL pour chaque vulnérabilité identifiée.
Les commandes ci-dessous doivent être exécutées pour installer les dépendances.
python3 -m venv path/to/venv
source path/to/venv/bin/activate
python3 -m pip install -r requirements.txt
La première commande crée un environnement virtuel dans le répertoire spécifié par path/to/venv.
La deuxième commande active l'environnement virtuel.
La dernière commande installe tous les paquets Python listés dans requirements.txt.
$ python3 graphql-cop.py -h
Usage: graphql-cop.py -t http://example.com -o json
Options:
-h, --help show this help message and exit
-t URL, --target=URL target url with the path - if a GraphQL path is not
provided, GraphQL Cop will iterate through a series of
common GraphQL paths
-H HEADER, --header=HEADER
Append Header(s) to the request '{"Authorization":
"Bearer eyjt"}' - Use multiple -H for additional
Headers
-o FORMAT, --output=FORMAT
json
-e EXCLUDED_TESTS, --excluded-tests=EXCLUDED_TESTS
Exclude specific tests
-l, --list-tests List available tests
-f, --force Forces a scan when GraphQL cannot be detected
-d, --debug Append a header with the test name for debugging
-x PROXY, --proxy=PROXY
HTTP(S) proxy URL in the form
http://user:pass@host:port
-w WORDLIST, --wordlist=WORDLIST
Path to a list of custom GraphQL endpoints
-v, --version Print out the current version and exit.
-T, --tor Sends the request through the Tor network (ensure Tor
is running and properly configured)
$ python3 graphql-cop.py -t https://mywebsite.com/graphql
[HIGH] Introspection Query Enabled (Information Leakage)
[LOW] GraphQL Playground UI (Information Leakage)
[HIGH] Alias Overloading with 100+ aliases is allowed (Denial of Service)
[HIGH] Queries are allowed with 1000+ of the same repeated field (Denial of Service)
$ python3 graphql-cop.py -t https://mywebsite.com/graphql -e field_duplication
[HIGH] Introspection Query Enabled (Information Leakage)
[LOW] GraphQL Playground UI (Information Leakage)
[HIGH] Alias Overloading with 100+ aliases is allowed (Denial of Service)
[HIGH] Queries are allowed with 1000+ of the same repeated field (Denial of Service)
python3 graphql-cop.py -t https://mywebsite.com/graphql -o json
{'curl_verify': 'curl -X POST -H "User-Agent: graphql-cop/1.2" -H '
'"Accept-Encoding: gzip, deflate" -H "Accept: */*" -H '
'"Connection: keep-alive" -H "Content-Length: 33" -H '
'"Content-Type: application/json" -d \'{"query": "query { '
'__typename }"}\' \'http://localhost:5013/graphql\'',
'description': 'Tracing is Enabled',
'impact': 'Information Leakage',
'result': False,
'severity': 'INFO',
'color': 'green',
'title': 'Trace Mode'},
{'curl_verify': 'curl -X POST -H "User-Agent: graphql-cop/1.2" -H '
'"Accept-Encoding: gzip, deflate" -H "Accept: */*" -H '
'"Connection: keep-alive" -H "Content-Length: 64" -H '
'"Content-Type: application/json" -d \'{"query": "query { '
'__typename @aa@aa@aa@aa@aa@aa@aa@aa@aa@aa }"}\' '
"'http://localhost:5013/graphql'",
'description': 'Multiple duplicated directives allowed in a query',
'impact': 'Denial of Service',
'result': True,
'severity': 'HIGH',
'color': 'red',
'title': 'Directive Overloading'}]
$ python3 graphql-cop.py -t https://mywebsite.com/graphql --proxy=http://127.0.0.1:8080 --header '{"Authorization": "Bearer token_here"}'
[HIGH] Introspection Query Enabled (Information Leakage)
[LOW] GraphQL Playground UI (Information Leakage)
[HIGH] Alias Overloading with 100+ aliases is allowed (Denial of Service)
[HIGH] Queries are allowed with 1000+ of the same repeated field (Denial of Service)
git clone https://github.com/dolevf/graphql-cop.git
cd graphql-cop
docker build -t graphql-cop:latest .
Vous pouvez exécuter le conteneur Docker et passer des arguments au script graphql-cop comme suit :
docker run --rm -it graphql-cop:latest -t <GRAPHQL_ENDPOINT> -H '{"<HEADER_KEY>": "<HEADER_VALUE>"}'
Voici un exemple d'exécution du conteneur :
docker run --rm -it graphql-cop:latest -t https://example.com/graphql -H '{"Authorization": "Bearer abc123xyz"}'
Pour une liste de toutes les options disponibles, exécutez :
docker run --rm -it graphql-cop:latest --help
Dépannage