Lack of Resources and Rate Limiting
Check List
Methodology
Black Box
Rate Limiting Password Reset Functionalities
1
2
3
4
5
API Brute Force on Login Endpoint
1
POST /api/login HTTP/1.1
Host: target.com
Content-Type: application/json
{"username":"victim","password":"WrongPass1"}2
3
4
5
High-Volume API Abuse (DoS Vector)
1
GET /api/search?q=test HTTP/1.1
Host: target.com
Authorization: Bearer token1232
3
4
5
White Box
Cheat Sheet
Last updated