performing-api-rate-limiting-bypass - Test APIs for rate-limit bypass vulnerabilities
Tests API throttling controls for bypasses involving headers, IPs, methods, versions, paths, accounts, and encoding schemes.
Tags
Updated: 2026-10-03Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Discover rate limits
- Analyze enforcement mechanisms
- Test IP spoofing headers
- Vary endpoint paths
- Switch HTTP methods
- Rotate account identifiers
Inputs
- Authorized target endpoints
- Acceptable request volumes
- Authentication tokens
- Request bodies
- Target API details
- Password lists
- CDN and WAF details
Outputs
- Rate-limit headers
- Rate-limit thresholds
- Bypass findings
- HTTP response statuses
- Rate-limit summary
Requirements
- Written authorization
- Python 3.10 or later
- requests library
- aiohttp library
- asyncio library
- Burp Suite Professional
- Turbo Intruder extension
- cURL
- CDN and WAF knowledge
