rspec/shared_content/secrets/impact/exceed_rate_limits.adoc

11 lines
507 B
Plaintext
Raw Normal View History

==== Exceeding rate limits
Using a leaked secret, an attacker may be able to make hundreds or thousands of
authenticated calls to an online service. It is common for online services to
enforce a rate limit to prevent their servers from being overwhelmed.
If an attacker is able to exceed a user-based rate limit, they may be able to
cause a denial of service for the user. If this continues over a long period of
time, the user may also be subject to additional fees or may have their account
terminated.