0Pricing
Node.js Backend Development Bootcamp · Pelajaran

Pembatasan Laju dan Perlindungan dari Brute Force

Lindungi API Node.js Anda dari penyalahgunaan, penolakan layanan, dan serangan pengisian kredensial dengan menerapkan pembatasan laju serta perlindungan brute force.

Pembatasan Laju dan Perlindungan dari Brute Force adalah pelajaran Node.js Backend Development Bootcamp gratis di CoddyKit. Ini adalah pelajaran 4 dari 4. Kamu bisa membaca pelajaran lengkapnya di bawah secara gratis — lalu praktikkan langsung di browser dengan editor kode bawaan dan tutor AI 24/7. Ini adalah bagian dari jalur belajar Node.js Backend Development Bootcamp, dan progresmu tersinkronisasi di web dan aplikasi CoddyKit. Kursus Node.js Backend Development Bootcamp mencakup 4 pelajaran total.

Bagian dari pelajaran ini belum diterjemahkan dan ditampilkan dalam bahasa Inggris.

Why Limit Requests?

Without limits, a single client can hammer your API thousands of times per second — scraping data, guessing passwords, or simply overloading the server.

Rate limiting caps how many requests a client may make in a time window.

Attacks Rate Limiting Prevents

Rate limiting is a frontline defense against:

  • Brute-force login attempts
  • Credential stuffing with leaked passwords
  • Denial-of-service floods
  • Scraping and API abuse

How Counting Works

A rate limiter tracks a counter per client (usually keyed by IP). Each request increments it; when the count exceeds the limit within the window, further requests are rejected with 429 Too Many Requests.

express-rate-limit

The express-rate-limit package adds rate limiting as middleware in a few lines. Configure the window and max requests.

const rateLimit = require('express-rate-limit');
const limiter = rateLimit({
  windowMs: 15 * 60 * 1000,
  max: 100
});

Applying the Limiter

Apply globally with app.use, or to specific routes. Once over the limit, clients automatically receive a 429 response.

app.use(limiter);
// or just protect one route:
app.use('/api/', limiter);

Stricter Limits on Login

Login endpoints are prime brute-force targets, so give them a tighter limit than the rest of your API.

const loginLimiter = rateLimit({
  windowMs: 10 * 60 * 1000,
  max: 5,
  message: 'Too many login attempts'
});
app.post('/login', loginLimiter, handler);

Shared Store for Multiple Servers

The default in-memory store does not work when you run multiple instances behind a load balancer — each has its own counter. Use a shared store like Redis so limits apply across all servers.

const RedisStore = require('rate-limit-redis');
const limiter = rateLimit({
  store: new RedisStore({ /* client */ }),
  max: 100,
  windowMs: 60000
});

Trusting the Real Client IP

Behind a proxy, every request appears to come from the proxy's IP. Tell Express to trust the proxy so the limiter keys on the real client IP from X-Forwarded-For.

app.set('trust proxy', 1);

Account Lockout

Beyond IP limits, track failed logins per account. After several failures, temporarily lock the account or require a CAPTCHA — defeating distributed brute-force from many IPs.

if (user.failedAttempts >= 5) {
  return res.status(423).json({ error: 'Account locked' });
}

Slowing Down Instead of Blocking

An alternative to hard blocks is progressive delay: each repeated request waits a little longer. The express-slow-down package adds latency rather than rejecting outright.

const slowDown = require('express-slow-down');
const speedLimiter = slowDown({
  windowMs: 60000,
  delayAfter: 50,
  delayMs: () => 500
});

Informing Clients

Good limiters send RateLimit headers telling clients their remaining quota and reset time, so well-behaved apps can back off gracefully.

const limiter = rateLimit({
  max: 100,
  windowMs: 60000,
  standardHeaders: true
});

Quick Check

Test your rate-limiting knowledge.

Recap

You learned to protect APIs from abuse:

  • Rate limiting caps requests per client and returns 429 when exceeded
  • express-rate-limit adds it as middleware; use stricter limits on login
  • Use a Redis store across multiple servers and set trust proxy for real IPs
  • Add account lockout, progressive slow-down, and informative headers

These layers thwart brute-force, scraping, and DoS attacks.

Pertanyaan yang Sering Diajukan

Apakah pelajaran “Pembatasan Laju dan Perlindungan dari Brute Force” gratis?

Ya — teks lengkap “Pembatasan Laju dan Perlindungan dari Brute Force” gratis dibaca di sini di web. Untuk praktiknya secara interaktif (editor kode bawaan dan tutor AI 24/7) dan buka sisa kursus Node.js Backend Development Bootcamp, upgrade ke CoddyKit PRO. Kursus Node.js Backend Development Bootcamp mencakup 4 pelajaran total.

Apa yang akan aku pelajari di “Pembatasan Laju dan Perlindungan dari Brute Force”?

Lindungi API Node.js Anda dari penyalahgunaan, penolakan layanan, dan serangan pengisian kredensial dengan menerapkan pembatasan laju serta perlindungan brute force. Kamu berlatih Node.js Backend Development Bootcamp dengan kode praktik yang langsung kamu jalankan di browser, dan tutor AI 24/7 menjawab pertanyaanmu saat kamu mengerjakan pelajaran ini.

Apakah aku perlu pengalaman untuk memulai Node.js Backend Development Bootcamp?

Tidak diperlukan pengalaman sebelumnya. Node.js Backend Development Bootcamp di CoddyKit dirancang untuk pemula hingga pelajar tingkat lanjut, jadi kamu bisa memulai di sini atau dari awal dan belajar sesuai kecepatan kamu sendiri. Ini adalah pelajaran 4 dari 4.

Berapa lama pelajaran “Pembatasan Laju dan Perlindungan dari Brute Force” memakan waktu?

Sebagian besar pelajaran CoddyKit memakan waktu sekitar 5–10 menit. Setiap pelajaran ringkas dan interaktif, jadi kamu membuat kemajuan stabil dan melanjutkan dari tempat kamu tinggalkan di web dan aplikasi.

Bisakah aku menulis dan menjalankan kode dalam pelajaran Node.js Backend Development Bootcamp ini?

Ya. Setiap pelajaran Node.js Backend Development Bootcamp menyertakan editor kode bawaan, jadi kamu menulis dan menjalankan kode nyata langsung di browser dan mendapatkan umpan balik AI instan — tidak diperlukan penyiapan lokal.

Semua pelajaran dalam kursus ini

  1. Memahami 10 Teratas OWASP
  2. Praktik Pengodean Aman di Node.js
  3. Enkripsi dan Hashing Data
  4. Pembatasan Laju dan Perlindungan dari Brute Force
← Kembali ke Node.js Backend Development Bootcamp