So basically someone is running a script iterates over the whole ipv4 range and calls the claim endpoint with each single adress in the X-Forwared-For http header once.
3r7j6qzi9jvnve · 1h ago
That only works if the proxy is sitting on localhost or a local network, just setting the header shouldn't work.
(I came here because I was curious how jart got 127 and 10, but after seeing the source is their's that's less of wonder..)
elitepleb · 1h ago
a simple proof of the opposite is that no one's yet to exploit any of the untaken ranges that way
Edit: looks like thats it: https://github.com/jart/cosmopolitan/blob/master/net/turfwar...
So basically someone is running a script iterates over the whole ipv4 range and calls the claim endpoint with each single adress in the X-Forwared-For http header once.
(I came here because I was curious how jart got 127 and 10, but after seeing the source is their's that's less of wonder..)