awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
rack avatar

rack/rack-attack

0
View on GitHub↗
5,746 stars·344 forks·Ruby·MIT·11 views

Rack Attack

Rack-attack is a middleware rate limiter and request filter for the Rack interface. It provides a system for throttling HTTP requests and maintaining IP address blocklists to protect applications from malicious traffic and denial-of-service attacks.

The project enables application layer DDoS mitigation and API rate limit management by identifying and rejecting requests from banned clients or abusive IP addresses. It allows for the definition of safelists to bypass filters and uses custom logic to determine if a client should be blocked or throttled.

The tool covers comprehensive traffic management through automated client banning, exponential backoff strategies, and the ability to define custom rejection responses. It includes instrumentation for monitoring request patterns and supports external cache backends to synchronize state across distributed application instances.

Features

  • Request Rate Limiting - Controls the number of requests a client can make within a specific timeframe to prevent system overload.
  • Request Interception Middleware - Intercepts incoming HTTP requests in a middleware pipeline to evaluate security rules before application processing.
  • External State Stores - Integrates with external state stores to maintain ban records and request counts across distributed instances.
  • Distributed Rate Limit Stores - Provides external cache backend integration to synchronize rate limiting state across distributed application instances.
  • Traffic Throttling - Limits request rates based on unique identifiers to prevent system overload and mitigate DoS attacks.
  • Automated IP Banning - Automatically blocks clients for a set duration after they exceed thresholds for forbidden requests or failures.
  • Malicious Traffic Blocking - Identifies and rejects requests from banned IP addresses or abusive clients before they reach application logic.
  • IP Blocking Middleware - Ships middleware that rejects traffic from forbidden IP addresses and subnets to protect the application.
  • Predicate-Based Request Filtering - Evaluates incoming requests against custom truthy logic blocks to determine safelisting, blocking, or throttling.
  • IP-Based Rate Limiting - Tracks request frequency using unique identifiers like IP addresses to apply granular per-user quotas.
  • Middleware Rate Limiters - Provides a middleware layer for the Rack interface to throttle HTTP requests and block abusive clients.
  • IP Address Blocklists - Maintains blocklists to identify and reject traffic from specific banned IP addresses.
  • API Rate Limiting - Provides tools for managing API request quotas and communicating limits via standard HTTP headers.
  • Rack Request Filters - Implements a filtering mechanism for Rack applications to evaluate requests against security rules and safelists.
  • Quota Status Headers - Implements HTTP response headers that communicate remaining request quotas and retry delays to API clients.
  • Throttled Response Customization - Allows defining custom HTTP response objects, status codes, and headers for blocklisted or throttled requests.
  • DDoS Protections - Protects Rack-based web applications from DDoS attacks by managing request rates and blocking abusive clients.
  • Request Safelisting - Permits trusted clients or specific requests to bypass all security filters and rate limits.
  • Layered Throttle Compositions - Implements layered throttle composition to apply multiple time-window limits for exponential backoff strategies.
  • Server-Side Backoff Enforcement - Implements layered throttles that progressively increase the wait time between requests for abusive clients.
  • Pipeline Short-Circuiting - Immediately returns custom HTTP responses when a request matches a blocklist, terminating the pipeline early.

Star history

Star history chart for rack/rack-attackStar history chart for rack/rack-attack

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to Rack Attack

Similar open-source projects, ranked by how many features they share with Rack Attack.
  • kickstarter/rack-attackkickstarter avatar

    kickstarter/rack-attack

    5,744View on GitHub↗

    This project is a Rack middleware rate limiter and application layer firewall for Ruby web applications. It serves as a security layer to throttle and block HTTP requests based on custom rules, protecting web servers from abusive traffic. The system provides capabilities for IP blocking and the banning of malicious clients. It implements request safelisting to bypass restrictions for trusted users and uses time-windowed rate limiting to control request frequency. The middleware covers traffic management and monitoring, including the ability to track request patterns and instrument traffic ev

    Ruby
    View on GitHub↗5,744
  • mitchellkrogza/nginx-ultimate-bad-bot-blockermitchellkrogza avatar

    mitchellkrogza/nginx-ultimate-bad-bot-blocker

    4,750View on GitHub↗

    This project is a collection of configuration files and scripts serving as a bot blocker and security middleware for Nginx. It functions as an automated blocklist manager that filters malicious user-agents and IP addresses to mitigate vulnerability scanning, login brute-forcing, and DDoS attacks. The system distinguishes itself by automating the maintenance of security rules, downloading updated bot definitions and reloading the server on a schedule. It also includes a search engine spam filter capable of generating robots.txt files and link disavow lists to prevent malicious domains from imp

    Shelladwarebot-blockerbots
    View on GitHub↗4,750
  • express-rate-limit/express-rate-limitexpress-rate-limit avatar

    express-rate-limit/express-rate-limit

    3,265View on GitHub↗

    This project is a middleware for the Express web framework designed to restrict request frequency and protect server capacity. It functions as a traffic throttler that intercepts incoming requests to evaluate and enforce limits based on client identity within defined time windows. The system distinguishes itself through a pluggable data store pattern that allows for distributed rate limiting. By delegating hit count storage to external databases, it ensures consistent request tracking across multiple server instances and maintains state across process restarts. The library provides comprehen

    TypeScriptapiexpressexpress-js
    View on GitHub↗3,265
  • throttled/throttledthrottled avatar

    throttled/throttled

    1,591View on GitHub↗

    Throttled is a Go library and middleware package for enforcing rate quotas and request thresholds on HTTP endpoints. It provides tools for tracking web request rates over specific time windows to control access frequency and manage traffic spikes. The core request evaluation relies on a token-bucket algorithm with sliding counters backed by fast memory stores, supplemented by pluggable storage backends for state persistence. Incoming requests are identified and grouped using flexible visitor-key parsers based on IP addresses, API keys, or custom parameters. The package integrates directly w

    Go
    View on GitHub↗1,591
See all 30 alternatives to Rack Attack→

Frequently asked questions

What does rack/rack-attack do?

Rack-attack is a middleware rate limiter and request filter for the Rack interface. It provides a system for throttling HTTP requests and maintaining IP address blocklists to protect applications from malicious traffic and denial-of-service attacks.

What are the main features of rack/rack-attack?

The main features of rack/rack-attack are: Request Rate Limiting, Request Interception Middleware, External State Stores, Distributed Rate Limit Stores, Traffic Throttling, Automated IP Banning, Malicious Traffic Blocking, IP Blocking Middleware.

What are some open-source alternatives to rack/rack-attack?

Open-source alternatives to rack/rack-attack include: kickstarter/rack-attack — This project is a Rack middleware rate limiter and application layer firewall for Ruby web applications. It serves as… mitchellkrogza/nginx-ultimate-bad-bot-blocker — This project is a collection of configuration files and scripts serving as a bot blocker and security middleware for… express-rate-limit/express-rate-limit — This project is a middleware for the Express web framework designed to restrict request frequency and protect server… throttled/throttled — Throttled is a Go library and middleware package for enforcing rate quotas and request thresholds on HTTP endpoints.… jhurliman/node-rate-limiter — Node-rate-limiter is a utility library for Node.js designed to throttle both incoming and outgoing traffic using… loveshell/ngx_lua_waf — ngx_lua_waf is an OpenResty web application firewall that uses Lua to filter malicious HTTP requests and block web…