{
  "id": 855134,
  "title": "AWS WAF Challenge: blocking bots before they reach the application",
  "url": "https://urgent.news/2026/08/14/aws-waf-challenge-bloquer-les-bots-avant-quils-natteignent",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-14T09:10:35.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/aws-builders/aws-waf-challenge-bloquer-les-bots-avant-quils-natteignent-lapplication-1np9"
  },
  "original_language": "fr",
  "account": "A client experienced two attacks on their applications, one targeting a historical server-side application and the other a single-page app (SPA) with a JSON API. The attacks generated millions of requests from numerous IP addresses, rendering IP blocking ineffective. The client initially tried to mitigate the attacks using Cloudflare Turnstile, but it only partially worked and had performance implications. The client then used AWS WAF's Challenge feature, which stopped requests without a valid token at the edge, reducing technical costs and improving performance. The Challenge feature was implemented in two modes: directly returned by WAF for an HTML page and resolved by challenge.js before being transmitted to an API.",
  "summary": "Quand on m’a appelé, l’attaque durait depuis environ une semaine. Elle visait la page de connexion d’une application historique qui générait son HTML côté serveur. Les requêtes se comptaient en millions et provenaient d’un très grand nombre d’adresses IP, ce qui rendait un blocage par IP peu efficace. Contrairement à d’autres campagnes que j’avais rencontrées, l’assaillant faisait également…",
  "key_points": [
    "Attack targeted legacy application's login page",
    "Million queries from vast IP addresses, ineffective IP blocking",
    "AWS WAF Challenge feature placed at infrastructure layer"
  ],
  "editors_take": "Moving bot-blocking to the infrastructure layer with AWS WAF Challenge reduces technical costs and improves performance by stopping unwanted queries at the edge, bypassing resource-intensive application validation processes.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}