BOOK THIS SPACE FOR AD
ARTICLE ADHello, hackers! I hope you’re having a great day. This is my first write-up, and I’d like to share how I bypassed a rate-limit filter using the “X-Forwarded-For” header.
First, I registered an account and checked the login page. I noticed that after 10 requests, the WAF (Web Application Firewall) would block my IP. I tried using different headers, including:
“X-Forwarded-Host”“X-Real-IP”“X-Original-IP”“X-Forwarded-For”With the “X-Forwarded-For” header, I successfully bypassed the WAF.
Source on HackerOne: https://hackerone.com/reports/2714304