3 ms·
I'm on a campus network that reverse proxies all HTTP traffic. The service shows my internal 10.x.x.x IP. Just a heads-up that you might want to fix your handli
by whitehat2k9 13y ago
I'm on a campus network that reverse proxies all HTTP traffic. The service shows my internal 10.x.x.x IP. Just a heads-up that you might want to fix your handling of X-Forwarded-For headers.
- jbverschoor 13y agoThat's a normal / forward proxy (transparent most likely)
- whitehat2k9 13y agoYou're absolutely right. I've being setting up too many nginx instances lately and the term stuck in my head...
- mike-cardwell 13y agoYeah. Should exclude any of these: 127.0.0.0/8, 10.0.0.0/8, 192.168.0.0/16 and the lesser known 172.16.0.0/12 Also, I wonder if it handles X-Forwarded-For headers that contain multiple IP addresses, because there are multiple levels of proxying taking place. Also. No IPv6? How boring.
- coderholic 13y agoThanks for reporting! You should see that we correctly detect this as a bogon, but we should definitely be pulling the correct IP from the headers. I'll look into this. $ curl ipinfo.io/10.0.0.1 { "ip": "10.0.0.1", "hostname": "No Hostname", "loc": "", "bogon": true }