Page 1 of 1

Pen Test - API Rate Limit

Posted: Fri Nov 18, 2022 8:55 am
by CJ@GCH
Hi there. First time on here, and I've turned up with a daft question.
We recently had a Pen Test on our servers, and we got one issue raised about the Nagios box - There was a lack of an API Rate Limit, and it was possible to send a large amount of login requests to the Nagios XI instance.

I may be missing something blindingly obvious, but is there a setting somewhere that can rate the login requests?
Any assistance would be gratefully received.
Cheers.

Re: Pen Test - API Rate Limit

Posted: Tue Dec 12, 2023 5:09 pm
by ajcoil
Hi CJ@GCH,

Thank you for reaching out!

Unfortunately, we don't currently have official support for rate limiting login requests. However, I will submit a feature request for doing so!

If you have any further questions, feel free to reach out!