← 문제 라이브러리
Security Advanced SECURITY-1297 · 16 min

A rate limiter on login works against direct traffic but not

The threshold is low and still bypassed because the source identity header is no longer authoritative on one route.

WAF / AppSecPro
시나리오

Abuse controls appear effective in one environment and …

구독하면 이어서 볼 수 있어요

이 문제의 전체 시나리오와 점검 체크리스트, 복구 순서, 모범 풀이는 Pro 구독에서 열립니다.

구독 안내 보기