Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

# Tool Submission for Rate-Limit Bypass Techniques #928

Open
Hashtag-AMIN opened this issue Aug 30, 2024 · 0 comments
Open

# Tool Submission for Rate-Limit Bypass Techniques #928

Hashtag-AMIN opened this issue Aug 30, 2024 · 0 comments

Comments

@Hashtag-AMIN
Copy link

Hashtag-AMIN commented Aug 30, 2024

Dear hacktricks team,

I hope this message finds you well.

I recently reviewed the Pentesting-Web section on rate-limit-bypass techniques in the HackTricks repository. While I found the shared techniques be highly valuable, I noticed that no specific tools are listed to assist with these methods.

To address this, I have developed a script designed for fuzzing and automating rate-limit bypass in WAFs and CDNs. This script incorporates several techniques, including:

  • Control of threads for fuzzing
  • Random delay control
  • Random User-Agent and header generation(Simulate Internal Network)
  • Proxy and TOR support
  • Chunking of wordlists for:
    • Round-robin proxy usage
    • TOR IP cycling

You can find more detailed information about the script's features in my GitHub repository: https://github.com/Hashtag-AMIN/hashtag-fuzz.

I would appreciate if you could review my tool and consider adding it to the relevant section of the HackTricks repository.

Thank you for your time and consideration.

Best regards,
Hashtag-AMIN

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant