rate limiting
Rate limit bypasses with header spoof, IP rotation, GraphQL aliasing and endpoint duplicates.
Quick answer
What is rate limiting?
Rate limit bypasses with header spoof, IP rotation, GraphQL aliasing and endpoint duplicates.
Articles
4
Beginner
0
Intermediate
3
Advanced
1
Intermediate level
30-click Account Takeover — OTP brute force + Email Normalization
Two separate flaws look minor. Together, they hand you full ATO knowing only the email. Real bounty: €560 and 12 minutes of exploitation.
URL shortener as a mass PII leak — extraction of ~300 people/hour
Low-entropy codes + no rate limiting + a ticket with no auth = enumeration of phone numbers, cards (BIN+last 4) and real customers' purchases.
Rate limit bypasses — IP rotation, header spoofing, casing and alternative endpoints
X-Forwarded-For, IP rotation with cloudfront IPs, path casing, encoding tricks, bucket race condition. How to find the gaps in throttling.
Advanced level
1Practice rate limiting with real labs
Apply the techniques in safe environments based on real bug bounty reports.
- hunters training
- 711
- labs from real reports
- 55
- completions
- 1,205
- in bounties practiced
- $213,970
hunters training
labs from real reports
completions
in bounties practiced
Stop reading about bugs and start hunting them
Create your free account and practice on labs based on real reports that paid out thousands of euros. The Academy is free forever.
No card · free Academy · cancel anytime