Skip to content

Rate Limiting

APIs often serve as critical entry points for attackers, making authentication and rate-limiting mechanisms essential for defense. This section focuses on evaluating these controls through testing for missing authentication, insecure token storage, and bypassing rate-limiting mechanisms. Each test should be conducted with explicit authorization and within legal boundaries.


Testing for Missing Authentication

Objective: Verify that all API endpoints require proper authentication.
Common Issues: Unauthenticated endpoints, lack of token validation, or weak credential enforcement.

Testing Method:
1. Access endpoints without credentials: Use tools like curl or Postman to send requests without authentication headers.
2. Check response codes: Look for 401 Unauthorized or 403 Forbidden responses.
3. Test brute-force scenarios: Attempt to guess credentials via automated scripts (e.g., hydra).

Example:

curl -X GET https://api.example.com/data -H "Authorization: Bearer <invalid_token>"
If the response is 401, the endpoint enforces authentication. If it returns data, the API is vulnerable.

Mitigation:
- Enforce OAuth 2.0, API keys, or JWT tokens.
- Validate tokens on the server side and reject expired/invalid ones.


Insecure Token Storage

Objective: Identify insecure storage practices for authentication tokens (e.g., cookies, local storage).
Common Issues: Tokens stored in plaintext, exposed via browser vulnerabilities (XSS), or insecure HTTP headers.

Testing Method:
1. Inspect client-side storage: Use browser developer tools to check localStorage or sessionStorage for tokens.
2. Intercept traffic: Use Burp Suite or Wireshark to capture tokens transmitted over HTTP.
3. Test for cookie security: Check if tokens are stored in cookies with HttpOnly and Secure flags.

Example:

# Check if a token is stored in localStorage (browser console)
localStorage.getItem('auth_token')
If the token is readable, it’s exposed to XSS attacks.

Mitigation:
- Store tokens in HTTP-only, secure cookies.
- Use encrypted storage (e.g., Android Keystore, iOS Keychain) for mobile apps.


Bypassing Rate Limiting

Objective: Determine if rate-limiting mechanisms can be bypassed to prevent abuse.
Common Issues: Misconfigured thresholds, lack of IP-based enforcement, or weak token rate limits.

Testing Method:
1. Send excessive requests: Use curl or tools like siege to flood endpoints.
2. Test IP rotation: Use proxies or multiple IPs to bypass IP-based limits.
3. Check rate-limit headers: Look for headers like X-RateLimit-Remaining to assess thresholds.

Example:

# Simulate rate-limit bypass using multiple IPs (via proxy)
curl -X POST https://api.example.com/endpoint -H "X-API-Key: <key>" --proxy http://proxy1.example.com
If the API accepts requests without enforcing limits, it’s vulnerable to abuse.

Mitigation:
- Implement IP-based rate limits with tools like NGINX or Cloudflare.
- Use token-based rate limiting with sliding window algorithms.


Key takeaways

  • Always verify that all API endpoints require authentication and validate tokens rigorously.
  • Securely store tokens using HTTP-only cookies or encrypted storage to prevent XSS leaks.
  • Test rate-limiting configurations to ensure they enforce thresholds and prevent abuse.
  • Use tools like Burp Suite, curl, and siege to automate and validate security controls.
  • Prioritize defense-in-depth by combining authentication, secure storage, and rate-limiting strategies.