Other nomination
Top 3 Proxy Issues That No One Ever Told You
Behind an inline caching proxy or cloud WAF the origin only ever sees the proxy's IP, so it trusts X-Forwarded-For. A null byte in that header name makes Apache answer 400 and rpaf log no client IP at all. TRACE sent through the proxy echoes what the proxy actually forwards, exposing any secret header the pair used to obfuscate the real client address.
Record
- Researcher
- Robert Hansen
- Published by
- WhiteHat Security
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Robert Hansen, first published at the original source. Preserved copies are kept so the citation survives its host.