Daily Writeups
3.87K subscribers
4 photos
134K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
⤷ Title: SecurityMetrics Wins “Data Leak Detection Solution of the Year” in 2025 CyberSecurity Breakthrough Awards Program
════════════════════════
𐀪 Author: CyberNewswire
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 12:45:49 +0000
════════════════════════
⌗ Tags: #Press Release #Cybersecurity #Data leak #SecurityMetrics #Vulnerability
⤷ Title: How To Uncover A Major Security Risk With One Line
════════════════════════
𐀪 Author: Ibtissam
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 13:58:07 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_security #xss_attack #ethical_hacking #cybersecurity
⤷ Title: The Day the Internet Died (For a Few Hours): Cloudflare Outage Explained
════════════════════════
𐀪 Author: Vaibhav Kumar Srivastava
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 12:53:50 GMT
════════════════════════
⌗ Tags: #hacking #security #cybersecurity #cloudflare #bugbounty_writeup
⤷ Title: The Unseen Engine: How the Linux Kernel Powers Our World
════════════════════════
𐀪 Author: IR0-k_oo1
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 12:51:52 GMT
════════════════════════
⌗ Tags: #hacking #kernal #linux #cybersecurity #arch_linux
⤷ Title: OSCP Grind | PG Practice | PayDay
════════════════════════
𐀪 Author: Mr Jokar
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 12:12:17 GMT
════════════════════════
⌗ Tags: #linpeas #oscp #infosec #cybersecurity #penetration_testing
⤷ Title: Detecting Web Shells Walkthrough. TryHackMe
════════════════════════
𐀪 Author: Lintu Oommen
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 13:32:03 GMT
════════════════════════
⌗ Tags: #webshell #cybersecurity #tryhackme_walkthrough #log_analysis
⤷ Title: Mastering Vulnerability Scanning: A Deep Dive into vuln-checker 0.5.5
════════════════════════
𐀪 Author: Skm248
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 13:29:44 GMT
════════════════════════
⌗ Tags: #software_security #vulnerability_management #automation_cli #cybersecurity #nvd_feeds
⤷ Title: A Day in the Life of a Cyber Security Analyst
════════════════════════
𐀪 Author: 464-Eshan
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 13:24:59 GMT
════════════════════════
⌗ Tags: #ai #digital_forensics #cybersecurity
⤷ Title: The Rise and Fall of Wally: How a Promising Web3 Project Collapsed and What Really Happened.
════════════════════════
𐀪 Author: Jinners
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 13:21:21 GMT
════════════════════════
⌗ Tags: #cybersecurity #crypto #solana_blockchain #memecoins #cryptocurrency
⤷ Title: Behind the scripts: chasing a clever ninja infostealer
════════════════════════
𐀪 Author: Dawid Bolkowski
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 13:19:36 GMT
════════════════════════
⌗ Tags: #malware #infostealer #reverse_engineering #digital_forensics #cybersecurity
⤷ Title: Building a Cyber Security Portfolio — Learning Step 2: Learning to teach
════════════════════════
𐀪 Author: Randy Puffin
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 13:19:16 GMT
════════════════════════
⌗ Tags: #personal_growth #cybersecurity #portfolio #knowledge_retention #learning
⤷ Title: SPF, DKIM, and DMARC: the three protocols protecting your inbox (and why you need all of them)
════════════════════════
𐀪 Author: Red Sift
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 13:15:20 GMT
════════════════════════
⌗ Tags: #dkim #spf #dmarc #cybersecurity #email_authentication
⤷ Title: The Importance of Online Security and How to Apply It
════════════════════════
𐀪 Author: Best Ecommerce Life
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 13:11:31 GMT
════════════════════════
⌗ Tags: #technology #digital_privacy #internet_safety #cybersecurity #online_security
⤷ Title: Building a Cyber Security Portfolio — Networking Step 2: Conferences
════════════════════════
𐀪 Author: Randy Puffin
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 13:02:17 GMT
════════════════════════
⌗ Tags: #social_media #personal_growth #meeting_people #cybersecurity #tech_conference
⤷ Title: Lposed module not working on android 16
════════════════════════
𐀪 Author: Jonsnow
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 13:45:49 GMT
════════════════════════
⌗ Tags: #magisk #android #mobile_penetration_test #mobile_security #penetration_testing
⤷ Title: eJPT v2 : Challenge Lab 26: Cheese
════════════════════════
𐀪 Author: Dhanushkumar R
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 12:56:35 GMT
════════════════════════
⌗ Tags: #cybersecurity #ctf #penetration_testing #security #tryhackme_walkthrough
⤷ Title: Understanding the Difference Between Penetration Testing and Red Teaming
════════════════════════
𐀪 Author: Beetles IO
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 12:09:13 GMT
════════════════════════
⌗ Tags: #redteam_tool #cybersecurity #red_teaming #penetration_testing
⤷ Title: Detecting Web Attacks Walkthrough. TryHackMe
════════════════════════
𐀪 Author: Lintu Oommen
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 12:42:23 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #tryhackme #wireshark
Forwarded from Bug Bounty Diary
✎ The perils of the “real” client IP & X-Forwarded-For Header

You've probably seen headers like these in common 403-bypass wordlists (e.g., my gist):
X-Forwarded-For: 127.0.0.1
X-Forwarded-Host: 127.0.0.1
X-Client-IP: 127.0.0.1

…and hundreds of similar variations (with 127.0.0.1, localhost, 192.168.1.1, internal IPs, etc.), but have you ever stopped to wonder why they sometimes actually work to bypass IP-based restrictions, rate limits, or 403/401 responses?

The answer lies in how unreliable and inconsistent the handling of "real client IP" headers is when a web application sits behind a reverse proxy (whether that’s a CDN like Cloudflare, an AWS ALB, a simple Nginx instance, etc.). It’s quite challenging for developers, because there’s no universal, standardized way for proxies to convey the original visitor’s IP to the backend and even less consensus on how the backend should parse and trust that information.

As a result, developers often rely on headers like X-Forwarded-For, X-Real-IP, or True-Client-IP to detect a visitor’s “real” IP address. But many frameworks use fragile logic especially the common pattern of trusting the left-most value in X-Forwarded-For. This is dangerous because the left-most entry is fully controlled by the client.

Cloudflare, AWS ALB, and many other proxies append the real IP to the header instead of overwriting it. So an attacker can send:
X-Forwarded-For: 127.0.0.1

and it becomes:
127.0.0.1, <real attacker IP>

Many libraries (like go-chi/httprate in Go) will mistakenly trust that spoofed first value. The app then believes the user is localhost or a trusted internal IP and may skip rate limits, authentication checks, or internal-only protections entirely.

This is not rare! dozens of frameworks and servers (Express, Jetty, IIS, Go libs, etc.) use inconsistent or insecure parsing strategies. The root problem: trusting client-controlled forwarding headers without restricting which proxies are allowed to set them.

•
I summarized the blog, but I highly recommend reading the full article here: Article

#bugbounty #recon #HTTP #bypass
© t.iss.one/BugBounty_Diary