AWS WAF Challenge: blocking bots before they reach the application
Quand on m’a appelé, l’attaque durait depuis environ une semaine. Elle visait la page de connexion d’une application historique qui générait son HTML côté serveur. Les requêtes se comptaient en millions et provenaient d’un très grand nombre d’adresses IP, ce qui rendait un blocage par IP peu efficace. Contrairement à d’autres campagnes que j’avais rencontrées, l’assaillant faisait également…
A client experienced two attacks on their applications, one targeting a historical server-side application and the other a single-page app (SPA) with a JSON API. The attacks generated millions of requests from numerous IP addresses, rendering IP blocking ineffective. The client initially tried to mitigate the attacks using Cloudflare Turnstile, but it only partially worked and had performance implications.
The client then used AWS WAF's Challenge feature, which stopped requests without a valid token at the edge, reducing technical costs and improving performance. The Challenge feature was implemented in two modes: directly returned by WAF for an HTML page and resolved by challenge.js before being transmitted to an API.
Written by urgent.news from Dev.to's report — not a translation of it. Machine-written — may contain errors; check the original before relying on it.