在一些CTF比赛常常会考到通过伪造IP获得flag,下面是一些常见的IP伪造的请求头:

  • X-Forwarded-For:127.0.0.1
  • Client-ip:127.0.0.1
  • X-Client-IP:127.0.0.1
  • X-Remote-IP:127.0.0.1
  • X-Rriginating-IP:127.0.0.1
  • X-Remote-addr:127.0.0.1
  • HTTP_CLIENT_IP:127.0.0.1
  • X-Real-IP:127.0.0.1
  • X-Originating-IP:127.0.0.1
  • via:127.0.0.1
  • X-Forwarded:127.0.0.1
  • X-Forwarded-Host:127.0.0.1
  • True-Client-IP:127.0.0.1
  • Ali-CDN-Real-IP:127.0.0.1
  • Cdn-Real-IP:127.0.0.1
  • Cdn-Src-IP:127.0.0.1
  • CF-Connecting-IP:127.0.0.1
  • Proxy-Client-IP:127.0.0.1