Bypass Rate-Limit via X-Forwarded-For

7 hours ago 8
BOOK THIS SPACE FOR AD
ARTICLE AD

Snoop-dog

Just now

--

Hello, hackers! I hope you’re having a great day. This is my first write-up, and I’d like to share how I bypassed a rate-limit filter using the “X-Forwarded-For” header.

First, I registered an account and checked the login page. I noticed that after 10 requests, the WAF (Web Application Firewall) would block my IP. I tried using different headers, including:

“X-Forwarded-Host”“X-Real-IP”“X-Original-IP”“X-Forwarded-For”

With the “X-Forwarded-For” header, I successfully bypassed the WAF.

Source on HackerOne: https://hackerone.com/reports/2714304

Read Entire Article