▲ | maverwa 5 days ago | |||||||
my first guess would be: server honors X-Forwarded-For where it should not? Edit: looks like thats it: https://github.com/jart/cosmopolitan/blob/master/net/turfwar... So basically someone is running a script iterates over the whole ipv4 range and calls the claim endpoint with each single adress in the X-Forwared-For http header once. | ||||||||
▲ | 3r7j6qzi9jvnve 5 days ago | parent | next [-] | |||||||
That only works if the proxy is sitting on localhost or a local network, just setting the header shouldn't work. (I came here because I was curious how jart got 127 and 10, but after seeing the source is their's that's less of wonder..) | ||||||||
| ||||||||
▲ | viraptor 5 days ago | parent | prev | next [-] | |||||||
The line just under that prevents public IPs from using that function. | ||||||||
| ||||||||
▲ | elitepleb 5 days ago | parent | prev [-] | |||||||
a simple proof of the opposite is that no one's yet to exploit any of the untaken ranges that way |