I’m not familiar with Graphql whatsoever, by doing some research, I was able to perform the following query on an open Graphql endpoint:
{
__type(name: "User") {
name
fields {
name
type {
name
kind
}
}
}
}
This responded with:
{
"data": {
"__type": {
"name": "User",
"fields": [
},
{
"name": "firstname",
"type": {
"name": "String",
"kind": "SCALAR"
}
},
{
"name": "lastname",
"type": {
"name": "String",
"kind": "SCALAR"
}
},
{
"name": "fullName",
"type": {
"name": "String",
"kind": "SCALAR"
}
},
},
{
"name": "title",
"type": {
"name": "String",
"kind": "SCALAR"
}
},
{
"name": "birthday",
"type": {
"name": "DateTime",
"kind": "SCALAR"
}
},
{
"name": "nationality",
"type": {
"name": "String",
"kind": "SCALAR"
}
}
]
}
}
}
Is there a way to extract the data from here? I’m basically testing to see if I can extract PII from this open Graphql endpoint. Any help would be greatly appreciated!