Back to Articles & Writeups
Security Research
8 MIN READ
2024-06-02

The Ultimate Rate Limiting & Concurrency Guide

Everything offensive researchers and defensive engineers need to know about testing and defeating rate limits in 2024.

AS
Sulaiman Hossain Sefat (Axo Solaman)Security Researcher • Student
The Ultimate Rate Limiting & Concurrency Guide
### Why Distributed Rate Limiting Fails Rate limiting sounds simple in theory: allow $N$ requests per unit of time $T$. In modern multi-region architectures, however, state synchronization across distributed caches introduces race windows. #### Common Attack Vectors 1. **Header Spoofing:** Naive reverse-proxy implementations trust client headers such as `X-Forwarded-For`, `X-Real-IP`, or `True-Client-IP`. 2. **Concurrency Windows (TOCTOU):** Multiple requests sent in parallel via HTTP/2 single-packet multiplexing hit the backend before the central Redis counter increments. 3. **Endpoint Path Normalization:** Utilizing URL casing (`/api/Login` vs `/api/login`) or path traversals (`/api/./login`) to evade URI-based rate limit rules.
#Guide#RateLimiting#Concurrency#AppSec
Syndicated on Medium