Challenge

Ask Nicely, Get Everything

Locke the pangolin

Locke grew up in the vault under Remitly's data center, where the walls are so thick even the servers whisper. Every scale on his back is a hardened perimeter he added after watching a real breach attempt bounce off. His motto: nothing gets in that wasn't invited.

But this account lookup tool doesn't live behind Locke's door. It talks to an API that never learned his rules — one that answers whatever it's asked, field by field, with no key required.

This application is intentionally vulnerable. Your goal is to find the hidden flag, in the format SPAM{this_is_an_example}. The container resets every 24 hours.

Results will appear here.

What is GraphQL Introspection + Missing Field-Level Authorization?

GraphQL APIs expose a single endpoint that answers whatever query you send it. Introspection lets any client ask the API to describe its own schema — every type, every field. Missing field-level authorization means the API checks whether you're allowed to query a type, but never whether you're allowed to see a specific field — so anyone who asks for a sensitive field by name gets it back.

Why is This Dangerous?

Front-end applications only request the fields they display, which creates a false sense of safety. "The UI never shows that data" is not the same as "the API won't return that data." Anyone willing to bypass the UI and talk to the API directly can request fields the UI never asked for — including internal notes, audit flags, or data never meant to leave the backend.

How to Prevent This?

References