| name | performing-api-rate-limiting-bypass |
| description | Use when tests API rate limiting implementations for bypass vulnerabilities by manipulating request headers, IP addresses, HTTP methods, API versions, and encoding schemes to circumvent request throttling controls. The tester identifies rate limit headers, determines enforcement mechanisms, and attempts bypasses including X-Forwarded-For spoofing, parameter pollution, case variation, and endpoint path manipulation. Maps to OWASP API4:2023 Unrestricted Resource Consumption. |
| domain | cybersecurity |
| tags | ["api-security","owasp","rate-limiting","throttling","brute-force","dos-prevention"] |
| subdomain | api-security |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["PR.PS-01","ID.RA-01","PR.DS-10","DE.CM-01"] |
Performing Api Rate Limiting Bypass
Overview
Cybersecurity skill for performing api rate limiting bypass. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"performing api rate limiting bypass"
-
"Tests API rate limiting implementations for bypass vulnerabilities by manipulati"
-
Testing whether API rate limiting can be circumvented to enable brute force attacks on authentication endpoints
-
Assessing the effectiveness of API throttling controls against credential stuffing or account enumeration
-
Evaluating if rate limits are enforced consistently across all API versions, methods, and encoding formats
-
Testing if API gateway rate limiting can be bypassed through header manipulation or IP rotation
-
Validating that rate limits protect against resource exhaustion and denial-of-service conditions
Do not use without written authorization. Rate limit testing involves sending high volumes of requests that may impact service availability.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Written authorization specifying target endpoints and acceptable request volumes
- Python 3.10+ with
requests, aiohttp, and asyncio libraries
- Burp Suite Professional with Turbo Intruder extension for high-speed testing
- cURL for manual header manipulation testing
- Knowledge of the target's CDN and WAF infrastructure (Cloudflare, AWS WAF, Akamai)
- List of rate-limit bypass headers to test
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def () -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}