top of page
erik biserovv
Admin
More actions
Profile
Join date: Apr 6, 2025
Posts (11)
Mar 1, 2026 ∙ 2 min
Case Study Distributed Rate Limiting Bypass
During an authentication security assessment, we discovered that the login endpoint's rate limiting was configured with per_edge counting on the CDN/WAF layer. The protection only triggered when concurrent connections exceeded a threshold (~30-50 simultaneous requests). By sending sequential requests—one at a time, waiting for each response—an authenticated attacker could perform unlimited login attempts without triggering any security controls. ...
2
0
Mar 1, 2026 ∙ 2 min
Front running mechanism in WEB3
Case Study: The $15 Attack That Could Block a Multi-Chain Protocol Blockchain technologies are different narrative and need to be looked from different angle to bring best value and contribute to safer environment. The Silent Threat Hiding in Plain Sight Centrifuge Protocol had ambitious plans. As a...
0
0
Mar 1, 2026 ∙ 2 min
Case study JWT access token with excessively long expiration
Scope: We was given Swagger documentation of company new service APIs for release We found that the application’s JWT access tokens (used for API authentication in most of the APIs) had an unusually long validity period (e.g., 7–30 days) and were not tied to any server‑side revocation or rotation mechanism. Once issued, a stolen token remained valid until its natural expiration, regardless of logout, password change, or role changes. This meant an attacker who obtained a single valid JWT...
0
0
bottom of page
