Missing rate limits on authentication endpoints

Missing rate limits on C# authentication endpoints

Description

Without effective rate limits on login or authentication requests, attackers can try many passwords, PINs, or tokens in a short time.

Potential impact

  • Brute-force and credential stuffing attacks may be more likely to succeed.
  • Authentication systems and log storage can experience excessive load.

Remediation

Use ASP.NET Core Rate Limiting middleware and apply an explicit policy to authentication endpoints with EnableRateLimiting or an equivalent mechanism. Also consider account lockouts, progressive delays, and MFA.

Examples

Before

csharp
[HttpPost("login")]
public IActionResult Login([FromBody] LoginRequest request)
{
    return Ok();
}

After

csharp
[EnableRateLimiting("login")]
[HttpPost("login")]
public IActionResult Login([FromBody] LoginRequest request)
{
    return Ok();
}

Explanation:

  • Before: Without an endpoint or global rate-limit policy, repeated authentication attempts are difficult to constrain.
  • After: EnableRateLimiting("login") applies the registered login policy. The example assumes that the policy is configured in AddRateLimiter and that UseRateLimiter runs after routing.

References