Collected research
Top 3 Proxy Issues That No One Ever Told You
Behind an inline caching proxy or cloud WAF the origin only ever sees the proxy's IP, so it trusts X-Forwarded-For. A null byte in that header name makes Apache answer 400 and rpaf log no client IP at all. TRACE sent through the proxy echoes what the proxy actually forwards, exposing any secret header the pair used to obfuscate the real client address.
Record
- Researcher
- Robert Hansen
- Published by
- WhiteHat Security
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Robert Hansen, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .