rate-limiting

2 articles
Sort: New Top Best
clear filter
0 5/10

Researcher bypassed 2FA on a private program by discovering that the 2FA verification endpoint did not validate the Google Captcha header (unlike the login endpoint), allowing brute-force of TOTP codes within the 59-second window using 888 threads in Burp Intruder.

Google Authenticator Burp Pro Turbo Intruder
shivangx01b.github.io · kh4sh3i/bug-bounty-writeups · 5 hours ago · details
0 5/10

A circuit breaker pattern designed to monitor and proactively limit resource consumption on metered serverless platforms like Cloudflare Workers, preventing unexpected overage charges by gracefully degrading functionality when usage thresholds are approached.

Cloudflare Workers Cloudflare KV AWS Budget Alerts Hystrix Lambda Vercel Supabase OpenAI Twilio 3mins.news
ethan_zhao · 2 days ago · details · hn