Danielle Rosenfeld-Lovell

Danielle is a Cyber Security professional with over 2 years of experience in the industry. She has predominately worked as a penetration tester. She tests a range of technologies, including, but not limited to web applications, APIs, cloud and on-prem infrastructure, and containers. She is particularly passionate about facilitating constructive communication between technical teams with different objectives. When she's not hacking things, you will find her reading, knitting, or hanging out with her cats.


Session

09-27
09:30
25min
OWASP Top 10 in GraphQL: An API Adventure
Danielle Rosenfeld-Lovell

Did you know that not all APIs are RESTful? Me neither at some point in the relatively recent past! This talk will explore bits and bobs related to GraphQL. We'll look at how it works, how to find GraphQL endpoints, and look at some GraphQL exploit techniques from the lens of the OWASP Top 10.

BSidesCbr 101
Bradman Theatrette