cancel
Showing results for 
Search instead for 
Did you mean: 
Read only

Security vulnerability using hybris OOB Maps feature

florianpeschke
Explorer
0 Likes
501

We have store locator / maps feature in our hybris webshop and we have faced and are facing a bot attack with over 4 million requests over the weekend (Feb 6 to Feb 😎 using the storelocator feature which in turn calls the google api. This feature is exposed for non logged in user.

  1. As a mitigation plan, we reduced the daily limit to 200 requests but that gets used up as bot attacks still happen.
  2. We tried to use the POST call instead of GET, but that doesn't help.

How can we stop such attacks in the future? The store location feature cannot be used as a result of bot attack ,we set up the daily limit to 200 to avoid charges on credit card caused due to google api requests from bot. The daily quota gets used up before start of business hours.

Thank you

Accepted Solutions (0)

Answers (0)