Credential Stuffing Prevention Test

Use the demo below to see how ShieldLabs protects a login page from account takeover, even when the password is correct.

In this demo, a login from an unknown device is challenged even with the right credentials, and repeated failed logins from the same browser are blocked.

How to use this demo

  1. Click Log in with the demo account that is filled in, user / password. You do not get in, even with the correct password, because this device is new to the account.
  2. Change the password to anything else and click Log in a few times. After 5 failed attempts, this device is blocked.
  3. Open this page in incognito mode and try again. The attempts still count against the same device.
  4. Try calling the login endpoint directly, or send a made-up request ID. The result is the same.
  5. You can reset this scenario with the Restart button at the top right.
Note

Clearing cookies and opening a private window within a few minutes gives one visitor several new cookies in quick succession. ShieldLabs reads that as automation, so for the next few minutes the demo refuses the request with a browser automation message.

Log in to your account