{"id":7078039,"date":"2026-10-06T11:15:21","date_gmt":"2026-10-06T11:15:21","guid":{"rendered":"https:\/\/fivemor.com\/?p=7078039"},"modified":"2026-10-06T11:15:21","modified_gmt":"2026-10-06T11:15:21","slug":"why-waf-and-rate-limiting-miss-residential-proxy-botnets","status":"publish","type":"post","link":"https:\/\/fivemor.com\/?p=7078039","title":{"rendered":"Why WAF and Rate Limiting Miss Residential Proxy Botnets"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articleBody\">\n<p>You might think your organization is adequately protected by the WAF and rate limiting you deploy, but think again. Legacy botnets rely on thousands of requests firing from a handful of data center IP addresses and are therefore easy to block with static rules, but modern distributed botnets operate very differently. These digital menaces use high-reputation residential proxy networks and rotate millions of IP addresses across infected smartphones, IoT devices, and compromised home routers (as well as opt-in proxy apps that sell user bandwidth) to look like legitimate human traffic.<\/p>\n<p>Why does this matter? Residential proxies act as effective camouflage for botnets, inheriting trust from ISPs, blending into legitimate traffic patterns, and bypassing static rules. To keep your enterprise safe from a potentially catastrophic botnet attack, you need to change your defense tactics.<\/p>\n<h2 id=\"the-move-to-low-and-slow-botnet-tactics\" tabindex=\"-1\">The move to &#8220;low and slow&#8221; botnet tactics<\/h2>\n<p>In the past, botnets&#8217; usual technique was to hammer endpoints, but this is no longer the case. The botnets of today, however, drip-feed malicious traffic into your system. Attack patterns now typically incorporate a single request per IP every five to fifteen minutes, thousands of unique IPs per minute, and distributed <a href=\"https:\/\/www.msn.com\/en-us\/money\/companies\/fbi-tallies-262m-lost-to-2025-account-takeovers-here-s-how-to-stay-safe\/ar-AA1RHY5f\" target=\"_blank\" rel=\"noopener\">account takeover<\/a> attempts across a vast IP pool. Credential stuffing may be spread across literally millions of devices, or inventory scalping disguised as normal browsing. This MO is the exact opposite of a volumetric DDoS. It&#8217;s quiet, patient, and designed to slip past your threshold-level defenses before you even realize there&#8217;s a problem.<\/p>\n<p><picture><source type=\"image\/avif\" srcset=\"https:\/\/i.macsecurity.net\/img\/Yz-pCPLrll-360-01-low-and-slow-botnet-rotating-residential-ips-bypass-waf.avif 360w, https:\/\/i.macsecurity.net\/img\/Yz-pCPLrll-510-01-low-and-slow-botnet-rotating-residential-ips-bypass-waf.avif 510w, https:\/\/i.macsecurity.net\/img\/Yz-pCPLrll-730-01-low-and-slow-botnet-rotating-residential-ips-bypass-waf.avif 730w, https:\/\/i.macsecurity.net\/img\/Yz-pCPLrll-1200-01-low-and-slow-botnet-rotating-residential-ips-bypass-waf.avif 1200w\" sizes=\"(max-width: 575px) calc(100vw - 30px), (max-width: 767px) 510px, (max-width: 991px) 690px, 730px\"><source type=\"image\/webp\" srcset=\"https:\/\/i.macsecurity.net\/img\/Yz-pCPLrll-360-01-low-and-slow-botnet-rotating-residential-ips-bypass-waf.webp 360w, https:\/\/i.macsecurity.net\/img\/Yz-pCPLrll-510-01-low-and-slow-botnet-rotating-residential-ips-bypass-waf.webp 510w, https:\/\/i.macsecurity.net\/img\/Yz-pCPLrll-730-01-low-and-slow-botnet-rotating-residential-ips-bypass-waf.webp 730w, https:\/\/i.macsecurity.net\/img\/Yz-pCPLrll-1200-01-low-and-slow-botnet-rotating-residential-ips-bypass-waf.webp 1200w\" sizes=\"(max-width: 575px) calc(100vw - 30px), (max-width: 767px) 510px, (max-width: 991px) 690px, 730px\"><source type=\"image\/jpg\" srcset=\"https:\/\/i.macsecurity.net\/img\/Yz-pCPLrll-360-01-low-and-slow-botnet-rotating-residential-ips-bypass-waf.jpg 360w, https:\/\/i.macsecurity.net\/img\/Yz-pCPLrll-510-01-low-and-slow-botnet-rotating-residential-ips-bypass-waf.jpg 510w, https:\/\/i.macsecurity.net\/img\/Yz-pCPLrll-730-01-low-and-slow-botnet-rotating-residential-ips-bypass-waf.jpg 730w, https:\/\/i.macsecurity.net\/img\/Yz-pCPLrll-1200-01-low-and-slow-botnet-rotating-residential-ips-bypass-waf.jpg 1200w\" sizes=\"(max-width: 575px) calc(100vw - 30px), (max-width: 767px) 510px, (max-width: 991px) 690px, 730px\"><img src=\"https:\/\/i.macsecurity.net\/img\/Yz-pCPLrll-360-01-low-and-slow-botnet-rotating-residential-ips-bypass-waf.jpg\" srcset=\"https:\/\/i.macsecurity.net\/img\/Yz-pCPLrll-360-01-low-and-slow-botnet-rotating-residential-ips-bypass-waf.jpg 360w, https:\/\/i.macsecurity.net\/img\/Yz-pCPLrll-510-01-low-and-slow-botnet-rotating-residential-ips-bypass-waf.jpg 510w, https:\/\/i.macsecurity.net\/img\/Yz-pCPLrll-730-01-low-and-slow-botnet-rotating-residential-ips-bypass-waf.jpg 730w, https:\/\/i.macsecurity.net\/img\/Yz-pCPLrll-1200-01-low-and-slow-botnet-rotating-residential-ips-bypass-waf.jpg 1200w\" sizes=\"auto, (max-width: 575px) calc(100vw - 30px), (max-width: 767px) 510px, (max-width: 991px) 690px, 730px\" alt=\"Low and slow botnet sending single requests from many rotating residential IP addresses past a WAF and rate limiter\" title=\"Low and slow botnet sending single requests from many rotating residential IP addresses past a WAF and rate limiter\" width=\"1200\" height=\"675\" loading=\"lazy\" decoding=\"async\"\/><\/source><\/source><\/source><\/picture><\/p>\n<h2 id=\"why-your-traditional-defenses-arent-enough\" tabindex=\"-1\">Why your traditional defenses aren&#8217;t enough<\/h2>\n<p>Legacy WAF logic focuses on blocking IPs that send more than 100 requests per minute, repeated login failures from the same IP, and known bad IP ranges. But this logic can easily break when residential IPs are rotated constantly, each IP sends almost no traffic, and reputation databases mark them as legitimate. Your rate-limiting defense doesn&#8217;t kick in because it doesn&#8217;t see anything &#8220;off&#8221;, while your WAF treats this malicious traffic as if it emanates from real human users.<\/p>\n<p>These rules assume attackers reuse IPs, but the problem is, modern botnets never do. In essence, a distributed botnet can execute hundreds of thousands of nefarious actions without triggering your rate-limiting or tripping your WAF rules.<\/p>\n<h2 id=\"ip-based-blocking-is-defunct\" tabindex=\"-1\">IP-based blocking is defunct<\/h2>\n<p>IP-based blocking is, today, not fit for purpose because IPs are no longer stable identifiers, and <a href=\"https:\/\/macsecurity.net\/view\/683-best-proxy-providers-for-teams\">residential proxies<\/a> inherit a &#8220;good&#8221; reputation, meaning these markers aren&#8217;t reliable. Botnets, determined to cause as much digital mischief as possible, rotate IPs faster than blocklists can update, and attackers mimic real human browsing behavior with alarming accuracy. On top of this, threshold rules can&#8217;t detect distributed patterns.<\/p>\n<p>There&#8217;s a growing industry consensus that a shift is required: from IP-based to intent-based defenses. These techniques include:<\/p>\n<ul>\n<li><strong>Intent modelling<\/strong> &#8211; analyzing what a user is trying to do.<\/li>\n<li><strong>Behavioral telemetry<\/strong> &#8211; collecting tiny behavioral signals.<\/li>\n<li><strong>Device fingerprinting<\/strong> &#8211; examining software and hardware characteristics.<\/li>\n<li><strong>Cross-request correlation<\/strong> &#8211; linking subtle behavioral cues across multiple sessions.<\/li>\n<li><strong>Velocity analysis across identities<\/strong> &#8211; measuring the speed and timing of actions.<\/li>\n<li><strong>Anomaly detection at scale<\/strong> &#8211; spotting deviations from normal behavior.<\/li>\n<\/ul>\n<p>Modern botnets exploit blind spots mercilessly, blending into legitimate traffic so effectively that legacy WAFs don&#8217;t even realize an attack is in progress. With malicious agents continuing to weaponize residential proxies, it&#8217;s only systems able to interpret intent that can protect themselves and fight back.<\/p>\n<h2 id=\"real-world-examples-of-waf-and-static-rules-failure-and-the-fallout\" tabindex=\"-1\">Real-world examples of WAF and static-rules failure &#8211; and the fallout<\/h2>\n<p>The limitations of WAF and rate-limiting defenses aren&#8217;t an abstract issue, and recent years have seen disastrous consequences. For example, a mid-sized retailer was targeted by a residential proxy botnet that initiated credential stuffing attacks across thousands of household IPs. As each IP sent only a small number of requests, the company&#8217;s WAF and rate limits never triggered because the traffic was low and slow. The consequences were dire, with tens of thousands of dollars in fraud losses racked up, and analyst workload quadrupling during the attack. Further, customer experience was severely impacted due to account lockouts, affecting brand trust and reputation.<\/p>\n<p>Meanwhile, a wide-ranging campaign using Popa and NetNut residential proxies attacked multiple industries (including healthcare, hospitality, and retail) to launch scraping and credential stuffing attacks. The problem was that WAFs reliant on IP reputation failed because the IPs appeared legitimate, so detection took days as the distributed traffic looked normal and harmless. As a consequence, a five- to seven-figure loss was incurred from account takeover and fraud, and SLA exposure went through the roof as IoT devices were used as proxy endpoints during the attack.<\/p>\n<p>Yet another business recently experienced repeated malicious traffic routed via residential proxies that its WAF and static-based rules didn&#8217;t identify. IP-reputation-only defenses were entirely bypassed, and rate limits imposed per IP were useless as each IP only sent minimal traffic. Making matters even more complicated, the business&#8217;s WAF generated up to 50% more false investigations, which overwhelmed analysts.<\/p>\n<h2 id=\"moving-to-intent-based-detection\" tabindex=\"-1\">Moving to intent-based detection<\/h2>\n<p>Intent-based detection is a security approach that looks at what the user is trying to do rather than where the request came from. It replaces IP-based rules with contextual, behavioral, and telemetry-focused analysis to reveal whether an action is automated or emanates from a real human user.<\/p>\n<p>In the modern world of digital security, intent is king, because while bots can spoof IPs, they can&#8217;t perfectly spoof human behavior across millions of devices. The result? Distributed botnets are exposed immediately.<\/p>\n<h2 id=\"the-datadome-advantage-multi-layered-ai-detection\" tabindex=\"-1\">The DataDome advantage: Multi-layered AI detection<\/h2>\n<p>DataDome&#8217;s <a href=\"https:\/\/datadome.co\/guides\/bot-protection\/how-to-stop-and-prevent-botnet-attacks-on-your-website-and-server\/\" target=\"_blank\" rel=\"noopener\">botnet prevention<\/a> tool solves the problem of residential proxies not triggering your WAF and rate-limiting safeguards. It looks at:<\/p>\n<ul>\n<li><strong>Microbehaviors<\/strong> like scroll velocity, mouse movements, and timing irregularities that bots find it hard to mimic, meaning it can identify automation even if an IP appears clean.<\/li>\n<li><strong>Navigation patterns<\/strong>, evaluating how users move through your site to identify sequences that distributed botnets replicate across a huge number of rotating residential IPs.<\/li>\n<li><strong>Browser integrity<\/strong>, with DataDome checking for signs of automation frameworks, tampering, or headless browser artefacts.<\/li>\n<li><strong>Device signals<\/strong>, inspecting software and hardware fingerprints to sniff out the sort of inconsistencies that are typical of botnet traffic, even when each request comes from a different device profile.<\/li>\n<li><strong>Latency anomalies<\/strong>, such as timing deviations that reveal automation, to catch bots that intentionally slow down requests and blend with human traffic.<\/li>\n<li><strong>Hidden telemetry<\/strong>, collecting and correlating subtle signals that bots can&#8217;t fully replicate across large residential proxy networks.<\/li>\n<li><strong>Trillions of daily signals<\/strong>, with DataDome&#8217;s AI engine processing a vast volume of intent data to instantly flag botnets no matter how widely traffic is distributed.<\/li>\n<\/ul>\n<p>Further, DataDome&#8217;s system evaluates signals lightning fast, with a processing time of under two minutes. This ensures bot detection occurs before pages are loaded without slowing down and annoying legitimate users.<\/p>\n<h2 id=\"stop-malicious-botnets-jumping-your-digital-defenses\" tabindex=\"-1\">Stop malicious botnets jumping your digital defenses<\/h2>\n<p>In today&#8217;s world, WAFs and rate-limiting are no longer enough to protect your system from malicious botnets using residential proxies that don&#8217;t trigger any alarm bells. For the best protection (and peace of mind), you need a solution like DataDome that instantly identifies distributed botnets without relying on blacklists and static rules. As a result, modern botnets&#8217; camouflage is stripped away, your WAF&#8217;s blind spots disappear, and your users are protected without the addition of latency or friction.<\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>You might think your organization is adequately protected by the WAF and rate limiting you deploy, but think again. Legacy botnets rely on thousands of requests firing from a handful of data center IP addresses and are therefore easy to block with static rules, but modern distributed botnets operate very differently. These digital menaces use [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":7078040,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11768],"tags":[238597,37916,31796,1485,12761,197525],"dealstore":[],"offerexpiration":[],"class_list":["post-7078039","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-apple-2","tag-botnets","tag-limiting","tag-proxy","tag-rate","tag-residential","tag-waf"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Why WAF and Rate Limiting Miss Residential Proxy Botnets - Som2ny Network<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/fivemor.com\/?p=7078039\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Why WAF and Rate Limiting Miss Residential Proxy Botnets - Som2ny Network\" \/>\n<meta property=\"og:description\" content=\"You might think your organization is adequately protected by the WAF and rate limiting you deploy, but think again. Legacy botnets rely on thousands of requests firing from a handful of data center IP addresses and are therefore easy to block with static rules, but modern distributed botnets operate very differently. These digital menaces use [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/fivemor.com\/?p=7078039\" \/>\n<meta property=\"og:site_name\" content=\"Som2ny Network\" \/>\n<meta property=\"article:published_time\" content=\"2026-10-06T11:15:21+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/i.macsecurity.net\/img\/Yz-pCPLrll-360-01-low-and-slow-botnet-rotating-residential-ips-bypass-waf.jpg\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/fivemor.com\/?p=7078039#article\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/?p=7078039\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\"},\"headline\":\"Why WAF and Rate Limiting Miss Residential Proxy Botnets\",\"datePublished\":\"2026-10-06T11:15:21+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/fivemor.com\/?p=7078039\"},\"wordCount\":1229,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/?p=7078039#primaryimage\"},\"thumbnailUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/10\/1r7eiYoZgy-1200x630-719-waf-rate-limiting-residential-proxies.jpg\",\"keywords\":[\"Botnets\",\"Limiting\",\"Proxy\",\"Rate\",\"Residential\",\"WAF\"],\"articleSection\":[\"Apple\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/fivemor.com\/?p=7078039#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/fivemor.com\/?p=7078039\",\"url\":\"https:\/\/fivemor.com\/?p=7078039\",\"name\":\"Why WAF and Rate Limiting Miss Residential Proxy Botnets - Som2ny Network\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/fivemor.com\/?p=7078039#primaryimage\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/?p=7078039#primaryimage\"},\"thumbnailUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/10\/1r7eiYoZgy-1200x630-719-waf-rate-limiting-residential-proxies.jpg\",\"datePublished\":\"2026-10-06T11:15:21+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/fivemor.com\/?p=7078039#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/fivemor.com\/?p=7078039\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/?p=7078039#primaryimage\",\"url\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/10\/1r7eiYoZgy-1200x630-719-waf-rate-limiting-residential-proxies.jpg\",\"contentUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/10\/1r7eiYoZgy-1200x630-719-waf-rate-limiting-residential-proxies.jpg\",\"width\":1200,\"height\":630},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/fivemor.com\/?p=7078039#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/fivemor.com\/?bp_activities=1\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Why WAF and Rate Limiting Miss Residential Proxy Botnets\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/fivemor.com\/#website\",\"url\":\"https:\/\/fivemor.com\/\",\"name\":\"Som2ny Network\",\"description\":\"Daily Deals\",\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/fivemor.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/fivemor.com\/#organization\",\"name\":\"Som2ny Network\",\"url\":\"https:\/\/fivemor.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"contentUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"width\":300,\"height\":86,\"caption\":\"Som2ny Network\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"caption\":\"admin\"},\"sameAs\":[\"https:\/\/fivemor.com\"],\"url\":\"https:\/\/fivemor.com\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Why WAF and Rate Limiting Miss Residential Proxy Botnets - Som2ny Network","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/fivemor.com\/?p=7078039","og_locale":"en_US","og_type":"article","og_title":"Why WAF and Rate Limiting Miss Residential Proxy Botnets - Som2ny Network","og_description":"You might think your organization is adequately protected by the WAF and rate limiting you deploy, but think again. Legacy botnets rely on thousands of requests firing from a handful of data center IP addresses and are therefore easy to block with static rules, but modern distributed botnets operate very differently. These digital menaces use [&hellip;]","og_url":"https:\/\/fivemor.com\/?p=7078039","og_site_name":"Som2ny Network","article_published_time":"2026-10-06T11:15:21+00:00","og_image":[{"url":"https:\/\/i.macsecurity.net\/img\/Yz-pCPLrll-360-01-low-and-slow-botnet-rotating-residential-ips-bypass-waf.jpg","type":"","width":"","height":""}],"author":"admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"admin","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/fivemor.com\/?p=7078039#article","isPartOf":{"@id":"https:\/\/fivemor.com\/?p=7078039"},"author":{"name":"admin","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371"},"headline":"Why WAF and Rate Limiting Miss Residential Proxy Botnets","datePublished":"2026-10-06T11:15:21+00:00","mainEntityOfPage":{"@id":"https:\/\/fivemor.com\/?p=7078039"},"wordCount":1229,"commentCount":0,"publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"image":{"@id":"https:\/\/fivemor.com\/?p=7078039#primaryimage"},"thumbnailUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/10\/1r7eiYoZgy-1200x630-719-waf-rate-limiting-residential-proxies.jpg","keywords":["Botnets","Limiting","Proxy","Rate","Residential","WAF"],"articleSection":["Apple"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/fivemor.com\/?p=7078039#respond"]}]},{"@type":"WebPage","@id":"https:\/\/fivemor.com\/?p=7078039","url":"https:\/\/fivemor.com\/?p=7078039","name":"Why WAF and Rate Limiting Miss Residential Proxy Botnets - Som2ny Network","isPartOf":{"@id":"https:\/\/fivemor.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/fivemor.com\/?p=7078039#primaryimage"},"image":{"@id":"https:\/\/fivemor.com\/?p=7078039#primaryimage"},"thumbnailUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/10\/1r7eiYoZgy-1200x630-719-waf-rate-limiting-residential-proxies.jpg","datePublished":"2026-10-06T11:15:21+00:00","breadcrumb":{"@id":"https:\/\/fivemor.com\/?p=7078039#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/fivemor.com\/?p=7078039"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/?p=7078039#primaryimage","url":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/10\/1r7eiYoZgy-1200x630-719-waf-rate-limiting-residential-proxies.jpg","contentUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/10\/1r7eiYoZgy-1200x630-719-waf-rate-limiting-residential-proxies.jpg","width":1200,"height":630},{"@type":"BreadcrumbList","@id":"https:\/\/fivemor.com\/?p=7078039#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/fivemor.com\/?bp_activities=1"},{"@type":"ListItem","position":2,"name":"Why WAF and Rate Limiting Miss Residential Proxy Botnets"}]},{"@type":"WebSite","@id":"https:\/\/fivemor.com\/#website","url":"https:\/\/fivemor.com\/","name":"Som2ny Network","description":"Daily Deals","publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/fivemor.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/fivemor.com\/#organization","name":"Som2ny Network","url":"https:\/\/fivemor.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/","url":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","contentUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","width":300,"height":86,"caption":"Som2ny Network"},"image":{"@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","caption":"admin"},"sameAs":["https:\/\/fivemor.com"],"url":"https:\/\/fivemor.com\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/7078039","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=7078039"}],"version-history":[{"count":0,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/7078039\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/media\/7078040"}],"wp:attachment":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=7078039"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=7078039"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=7078039"},{"taxonomy":"dealstore","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdealstore&post=7078039"},{"taxonomy":"offerexpiration","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fofferexpiration&post=7078039"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}