Breaking The Graphql Bookstore API
A Step by Step walkthrough on the graphql bookstore lab
Read write-up →$ whoami
Application Security×Bug Hunter×Chess Player
Cybersecurity student exploring application security, bug bounty hunting, security research, and building things along the way.

$ cat /home/kwesilarry/about
I'm Kwesi Larry, also known online as 0xWizard.
This is my corner of the internet where I document what I'm learning, building, breaking, and researching.
My main focus is application security and bug hunting, with interests spanning web security, APIs, security engineering, robotics, and embedded systems.
$ ls interests/
$ _
GET IN TOUCH
Have a security project, collaboration, research opportunity, or just want to talk security? Feel free to reach out.
LATEST
A Step by Step walkthrough on the graphql bookstore lab
Read write-up →A walkthrough on th DVRA lab
Read write-up →A practical walkthrough of Server-Side Request Forgery vulnerabilities, covering all PortSwigger SSRF labs from basic exploitation to advanced internal-service attacks.
Read write-up →