Web Hack List

Collected research

Top 3 Proxy Issues That No One Ever Told You

Behind an inline caching proxy or cloud WAF the origin only ever sees the proxy's IP, so it trusts X-Forwarded-For. A null byte in that header name makes Apache answer 400 and rpaf log no client IP at all. TRACE sent through the proxy echoes what the proxy actually forwards, exposing any secret header the pair used to obfuscate the real client address.

Record

Researcher
Robert Hansen
Published by
WhiteHat Security
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Robert Hansen, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .