> For the complete documentation index, see [llms.txt](https://gitbook.seguranca-informatica.pt/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://gitbook.seguranca-informatica.pt/tools/web-and-and-dns/graphql.md).

# GraphQL

[**GraphQL:**](https://github.com/graphql/graphiql) GraphQL IDE Monorepo.

![](/files/-MWzxGbcTsw1VEN7ot_d)

&#x20;[**GraphQLmap**](https://github.com/swisskyrepo/GraphQLmap)**:** A scripting engine to interact with a graphql endpoint for pentesting purposes.

&#x20;[**InQL**](https://github.com/doyensec/inql) **+ burpsuite:** InQL can be used as a stand-alone script, or as a Burp Suite extension (available for both Professional and Community editions).&#x20;

![](/files/-MWzymn1zYVDU75wjfMX)

{% tabs %}
{% tab title="Configuration Burpsuite" %}
![](/files/-MX--czECRwHJ2q3EhMu)

Add Bearer- token

![](/files/-MX-050f6dSTlmR2TFvp)

Use the context menu to send it to the Repeater (***inql: Sent to graphiQL***)

![](/files/-MX-0a_TT6wDRiSIEVmI)

![](/files/-MgHreOpnoe2BXcuS_4a)
{% endtab %}
{% endtabs %}

## References

{% embed url="<https://busk3r.medium.com/hacking-graphql-for-fun-and-profit-part-1-understanding-graphql-basics-72bb3dd22efa>" %}

{% embed url="<https://busk3r.medium.com/hacking-graphql-for-fun-and-profit-part-2-methodology-and-examples-5992093bcc24>" %}
