在做CTF题目时,遇到需要伪造IP来找到Flag,这里记录一下。
 虽有多种方法可用,但实际使用中基本X-Forwarded-For就足够。
如果遇到需要更换多次IP后才能得出Flag的情况,可在Burpsuite中使用burpFakeIP插件完成伪造IP爆破。
X-Forwarded-For:127.0.0.1
  
 X-Forwarded:127.0.0.1
  
 Forwarded-For:127.0.0.1
  
 Forwarded:127.0.0.1
  
 X-Forwarded-Host:127.0.0.1
  
 X-remote-IP:127.0.0.1
  
 X-remote-addr:127.0.0.1
  
 True-Client-IP:127.0.0.1
  
 X-Client-IP:127.0.0.1
  
 Client-IP:127.0.0.1
  
 X-Real-IP:127.0.0.1
  
 Ali-CDN-Real-IP:127.0.0.1
  
 Cdn-Src-Ip:127.0.0.1
  
 Cdn-Real-Ip:127.0.0.1
  
 CF-Connecting-IP:127.0.0.1
  
 X-Cluster-Client-IP:127.0.0.1
  
 WL-Proxy-Client-IP:127.0.0.1
  
 Proxy-Client-IP:127.0.0.1
  
 Fastly-Client-Ip:127.0.0.1
  
 True-Client-Ip:127.0.0.1
Host: 127.0.0.1


