> For the complete documentation index, see [llms.txt](https://ctf.laet4x.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ctf.laet4x.com/ctf-2021/htb-business-ctf-2021/noteql.md).

# NoteQL

Challenge: NoteQL

Category: Web

<figure><img src="/files/aAEVINoSkDumgum1Fcwj" alt=""><figcaption></figcaption></figure>

The application is a note-taking application that uses GraphQL to save and fetch notes. I forgot to screenshots the main page of the challenge but our goal is to get the Hidden/Admin Notes.

I use Burpsuite to observe the GraphQL request and response.

<figure><img src="/files/OtWqMg2A7Pz7hTznDknJ" alt=""><figcaption></figcaption></figure>

The default query is:

`{“query” : “{ MyNotes {id, title, completed}}”}`

I tried to change the MyNotes to Notes (guess), but I found an interesting response. Notes do not exist, but the response suggests other Notes, such as **Note, MyNotes, and AllNotes.**

<figure><img src="/files/Wqi8PQ0EGlV98GBsFtXN" alt=""><figcaption></figcaption></figure>

I change the query into **AllNotes**, then I found the flag at **id:3, title: HTB{n0b0dy\_c0ntr0ls\_m3!!}**

<figure><img src="/files/rCnWeJ0uVRGYYJT28UPZ" alt=""><figcaption></figcaption></figure>
