DEV Community

Daniel Ioni
Daniel Ioni

Posted on

πŸ›‘οΈ Testing API Security with BruteForceAI: MyZubster Case Study

 # πŸ›‘οΈ Testing API Security with BruteForceAI: MyZubster Case Study

The Mission 🎯

Security is not optional. It's a requirement.

I recently integrated BruteForceAI into the MyZubster Gateway to test the security of our authentication system. The goal was simple: find vulnerabilities before the bad guys do.


πŸ€– What is BruteForceAI?

BruteForceAI is an open-source penetration testing tool that uses LLM (Large Language Models) to automate brute-force attacks.

How It Works

  1. Analyze β€” LLM identifies CSS selectors of login forms (95% accuracy)
  2. Attack β€” Multi-threaded attacks with human-like behavior (random delays, user-agent rotation)
  3. Report β€” SQLite database for audit and logs

Key Features

Feature Description
Brute-Force Mode Test all username/password combinations
Password Spray Mode Test one password on multiple accounts
Evasion Detection Delay, jitter, proxy, user-agent rotation
Notifications Discord, Slack, Teams, Telegram
Logging SQLite database for audit
LLM Providers Ollama (local) or Groq (cloud)

πŸ—οΈ Architecture

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ SECURITY TESTING ARCHITECTURE β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ β”‚
β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚
β”‚ β”‚ BruteForceAI │────▢│ MyZubster │────▢│ Authentication β”‚ β”‚
β”‚ β”‚ (Python) β”‚ β”‚ Gateway β”‚ β”‚ (JWT) β”‚ β”‚
β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚
β”‚ β”‚ β”‚ β”‚ β”‚
β”‚ β–Ό β–Ό β–Ό β”‚
β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚
β”‚ β”‚ TEST RESULTS β”‚ β”‚
β”‚ β”‚ β€’ 25 attempts (5 users Γ— 5 passwords) β”‚ β”‚
β”‚ β”‚ β€’ 0 successful logins β”‚ β”‚
β”‚ β”‚ β€’ 100% failure rate β”‚ β”‚
β”‚ β”‚ β€’ No vulnerabilities found β”‚ β”‚
β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚
β”‚ β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
text


πŸ’» Implementation

1. Setup BruteForceAI


bash
# Clone the repository
git clone https://github.com/MorDavid/BruteForceAI.git
cd BruteForceAI

# Create virtual environment
python3 -m venv .venv
source .venv/bin/activate

# Install dependencies
pip install -r requirements.txt
playwright install chromium

# Install Ollama (local LLM)
curl -fsSL https://ollama.ai/install.sh | sh
ollama pull llama3.2:3b

2. API Brute-Force Test Script

Since BruteForceAI is designed for web forms, I created a custom script for API testing:
javascript

// test-bruteforce-api.js
const axios = require('axios');

const users = ['admin', 'test', 'investor', 'user', 'danielioni'];
const passwords = ['Admin@2024', 'password123', 'admin123', 'test123', 'investor123'];

async function testLogin(username, password) {
  try {
    const response = await axios.post('http://localhost:3000/api/auth/login', {
      email: username,
      password: password
    });

    if (response.status === 200) {
      console.log(`βœ… SUCCESS: ${username}:${password}`);
      return true;
    }
  } catch (error) {
    if (error.response?.status === 401) {
      console.log(`❌ FAILED: ${username}:${password}`);
    }
  }
  return false;
}

async function runBruteforce() {
  console.log('πŸš€ Starting API brute-force test...\n');

  for (const user of users) {
    for (const pass of passwords) {
      await testLogin(user, pass);
    }
  }

  console.log('\nβœ… Test completed!');
}

runBruteforce();

3. BruteForceAI Command (Web Forms)
bash

# Analyze login forms with LLM
python BruteForceAI.py analyze \
  --urls targets.txt \
  --llm-provider ollama \
  --llm-model llama3.2:3b

# Password spray attack (safe mode)
python BruteForceAI.py attack \
  --urls targets.txt \
  --usernames users.txt \
  --passwords passwords.txt \
  --threads 1 \
  --delay 5 \
  --jitter 3 \
  --mode passwordspray

πŸ“Š Test Results
API Brute-Force Results
Metric  Value
Total Attempts  25 (5 users Γ— 5 passwords)
Successful  0
Failed  25
Success Rate    0%
Vulnerabilities None found
User/Password Combinations Tested
User    Attempts    Successes
admin   5   0
test    5   0
investor    5   0
user    5   0
danielioni  5   0

All attempts returned 401 Unauthorized βœ…
πŸ›‘οΈ Security Measures Already in Place
1. JWT Authentication

    Short-lived tokens (7 days)

    Secure secret management via environment variables

    Role-based access control (user, investor, admin, superadmin)

2. Password Security

    bcrypt hashing (12 salt rounds)

    Minimum 8 characters

    Secure password validation

3. API Protection

    CORS properly configured

    Helmet.js for security headers

    Rate limiting (coming soon)

    Input validation via Joi

πŸ”§ Lessons Learned
What Worked

    βœ… BruteForceAI setup was straightforward

    βœ… LLM integration with Ollama worked locally

    βœ… API security proved to be robust

    βœ… Scripted testing provided clear results

What Didn't Work

    ❌ BruteForceAI with Playwright β€” The tool is designed for HTML forms, not JSON APIs

    ❌ Ollama request errors β€” Some issues with the LLM API calls

    ❌ Headless browser dependencies β€” Required additional system libraries

What We Improved

    πŸ”„ Created custom API testing script for REST endpoints

    πŸ”„ Documented security measures for future reference

    πŸ”„ Identified areas for improvement (rate limiting, 2FA)

πŸš€ Next Steps
Priority    Feature Description
High    Rate Limiting   Prevent brute-force attacks
Medium  2FA Add TOTP authentication
Medium  Logging Audit all login attempts
Low CAPTCHA After multiple failed attempts
Low Monitoring  Real-time security alerts
Rate Limiting Implementation
javascript

// middleware/rateLimit.js
const rateLimit = require('express-rate-limit');

const limiter = rateLimit({
  windowMs: 15 * 60 * 1000, // 15 minutes
  max: 100, // 100 attempts per IP
  message: {
    success: false,
    message: 'Too many attempts, please try again later'
  }
});

πŸ“ Project Structure
text

~/MyZubsterGateway/
β”œβ”€β”€ src/
β”‚   β”œβ”€β”€ middleware/
β”‚   β”‚   β”œβ”€β”€ auth.js
β”‚   β”‚   β”œβ”€β”€ error.js
β”‚   β”‚   └── rateLimit.js (coming soon)
β”‚   β”œβ”€β”€ controllers/
β”‚   β”œβ”€β”€ routes/
β”‚   └── utils/
β”œβ”€β”€ BruteForceAI/
β”‚   β”œβ”€β”€ .venv/
β”‚   β”œβ”€β”€ targets.txt
β”‚   β”œβ”€β”€ users.txt
β”‚   β”œβ”€β”€ passwords.txt
β”‚   └── BruteForceAI.py
β”œβ”€β”€ test-bruteforce-api.js
└── README.md

πŸ”— Connect With Me
Platform    Link
Telegram Bot    @myzubster_bot
Telegram Channel    t.me/myzubster
GitHub  github.com/DanielIoni-creator/tokenization-singapore
Twitter/X   @MyZubster
YouTube youtube.com/@myzubster
Dev.to  dev.to/danielioni
πŸ’¬ Discussion

What security measures do you use for your APIs?

    πŸ”’ Do you use rate limiting?

    πŸ”‘ Do you implement 2FA?

    πŸ§ͺ Do you regularly test your security?

Let's discuss in the comments! πŸ‘‡
πŸ“š Resources

    BruteForceAI GitHub

    Ollama - Local LLM

    Express Rate Limit

    JWT Security Best Practices

Stay secure, stay safe. πŸ›‘οΈ

Built with ❀️ by Daniel Ioni and the MyZubster team.

Last updated: July 27, 2026
text
Enter fullscreen mode Exit fullscreen mode

Top comments (0)