← SecurityCédric MerlinFREN

Security galaxy Case 4 of 5

Five downloads in under a minute

The problem

A bot was downloading a website’s free guides through its public form: six in two days, five of them in under a minute.

The constraint

Block the bots without a third-party captcha that tracks visitors.

What I did

01

Audit

A captcha was in the code, but had never been turned on.

02

Signed token

The server signs each form, and a token works only once.

03

Decoy field

Invisible to a human, filled in by bots.

04

Rate limit

It holds even after a redeployment.

Diagram: a bot and a visitor in front of the same formAt the start, the captcha is off and a bot sends six accepted requests. At the end, the server issues a single-use signed token: the visitor gets through, the bot is refused. An invisible decoy field gives the bot away. A rate bucket fills up, overflows, refuses the following requests and keeps its level after a redeployment.botvisitorcaptchanever oninvisible to humanstokenserver

The result

Bots fail, and visitors notice no difference.

Stack

  • HMAC
  • Node.js