APIs without rate limiting are vulnerable to brute force attacks, credential stuffing, enumeration, and resource exhaustion (DoS). This maps to OWASP API4:2023 — Unrestricted Resource Consumption.
💡 Always test OTP/2FA endpoints, password reset endpoints, and login endpoints for missing rate limiting. These are consistently found in bug bounty programs.
Verify exercises to earn ★ 130 XP and unlock next lab level.