Credential Stuffing Prevention Test
Use the demo below to see how ShieldLabs protects a login page from account takeover, even when the password is correct.
In this demo, a login from an unknown device is challenged even with the right credentials, and repeated failed logins from the same browser are blocked.
How to use this demo
- Click Log in with the demo account that is filled in,
user/password. You do not get in, even with the correct password, because this device is new to the account. - Change the password to anything else and click Log in a few times. After 5 failed attempts, this device is blocked.
- Open this page in incognito mode and try again. The attempts still count against the same device.
- Try calling the login endpoint directly, or send a made-up request ID. The result is the same.
- You can reset this scenario with the Restart button at the top right.
Note
Clearing cookies and opening a private window within a few minutes gives one visitor several new cookies in quick succession. ShieldLabs reads that as automation, so for the next few minutes the demo refuses the request with a browser automation message.