Description
Without effective rate limits on login or authentication requests, attackers can try many passwords, PINs, or tokens in a short time.
Potential impact
- Brute-force and credential stuffing attacks may be more likely to succeed.
- Authentication systems and log storage can experience excessive load.
Remediation
Use ASP.NET Core Rate Limiting middleware and apply an explicit policy to authentication endpoints with EnableRateLimiting or an equivalent mechanism. Also consider account lockouts, progressive delays, and MFA.
Examples
Before
csharp
[HttpPost("login")]
public IActionResult Login([FromBody] LoginRequest request)
{
return Ok();
}
After
csharp
[EnableRateLimiting("login")]
[HttpPost("login")]
public IActionResult Login([FromBody] LoginRequest request)
{
return Ok();
}
Explanation:
- Before: Without an endpoint or global rate-limit policy, repeated authentication attempts are difficult to constrain.
- After:
EnableRateLimiting("login")applies the registeredloginpolicy. The example assumes that the policy is configured inAddRateLimiterand thatUseRateLimiterruns after routing.