No Rate Limiting Bypass | POC | Bug Bounty | 2020

Опубликовано: 06 Май 2026
на канале: Exploits Simplified
10,742
229

Introduction

A little bit about Rate Limit:
A rate limiting algorithm is used to check if the user session (or IP-address) has to be limited based on the information in the session cache.

In case a client made too many requests within a given timeframe, HTTP-Servers can respond with status code 429: Too Many Requests


Steps To Reproduce The Issue:

Step 1-Go To This Link https://www.example.com/login
Enter Email Click On Next as shown in video attached

step-2-intercept the request and send to intruder

step-3-go for null payloads as shown in the screenshot attached

step-4-And you will get 200 resonse which means email sent successfully to the email.


#bug, #bounty, #bugbounty, #owasp, #webapps, #hacking, #ethical, #ethicalhacking, #bugcrowd, #vulnerability, #security, #cyber, #cybersecurity, #webattacks,