Web - Server

Saturday 1 May 2021, 12:10  #1
Web - Server HTTP - IP restriction bypass
SarisinKurt
  • 1 posts

Hi all,

I wanted to ask you help, I try to solve this for a couple hours now can you please help me ?

I think that I have to connect to the internal network but I don’t know how.

Saturday 8 May 2021, 14:35  #2
Web - Server HTTP - IP restriction bypass
PAranoidx0x0
  • 1 posts

Same question Did you find solution

Sunday 30 May 2021, 16:20  #3
Web - Server HTTP - IP restriction bypass
Z£r0Day
  • 1 posts

Read very well the instructions and also the related resource of the challenge

Sunday 6 June 2021, 19:00  #4
Web - Server HTTP - IP restriction bypass
Samat_94
  • 1 posts

I have the same problem, is the answer is close to DNS?

Wednesday 7 July 2021, 08:27  #5
Web - Server HTTP - IP restriction bypass
beta
  • 1 posts

Yes read Page 6 last paragraph

Thursday 9 September 2021, 20:02  #6
Web - Server HTTP - IP restriction bypass
humusk
  • 1 posts

Connecting to the challenge using their internal IP doesn’t work. Using a proxy to change your requests to act like your using the private DNS doesn’t work. Not sure what else to do, too bad none of the people who have done it are much help besides "read the description". Hopefully this level of ’help’ isn’t the norm on this site....

Sunday 12 September 2021, 13:27  #7
[Solved] Web - Server HTTP - IP restriction bypass
h4r5h
  • 2 posts

if anyone is stil finding answer then i can help you i was struggling almost for 2-3 day but now i solved it
here are some hints:-
1. Search on google how to bypass ip (medium’s blog)
2. use proxy like burp suite
Final and main
3. Check all request is forwarded toward server so change which will make request unsecure
Hope you can solve it now

Friday 17 September 2021, 18:25  #8
Web - Server HTTP - IP restriction bypass
kirby
  • 2 posts

hi
can u explain more what u did plz im stuck also, i thought i was supposed to find the login information somewhere in the src but i was wrong and i dont understand what u said u did.

Friday 17 September 2021, 21:28  #9
Web - Server HTTP - IP restriction bypass
kirby
  • 2 posts

i just looked at the blog and solved it, thanks.

Monday 10 January 2022, 14:35  #10
Web - Server HTTP - IP restriction bypass
Jatayu
  • 2 posts

Here is the problem I think exists with this challenge. The actual vulnerability is the concept of the intermediary proxy server and the web server’s reliance on X-Forwarded-For header. Once you know this much you can easily think how to at least make it theoretically work. All you need is a machine with a static IP which is under your control at your disposal where you can have run a dummy proxy server to receive the messages.
While doing these challenges the assumption is that they are intended to help people learn. But the RFC document has no mention of any particular approach on implementation. It simply explains what it is. An experienced professional might already know this but there is no point for them to attend these challenges except to feel good or refresh. This makes such challenges totally useless for learners like me. Yes, you might argue that this is what is expected in real world circumstances but we too know that. The whole point of using a site like this is to learn and resources are expected to contain material which have some relation to what can be exploited.

Monday 10 January 2022, 14:39  #11
Web - Server HTTP - IP restriction bypass
Jatayu
  • 2 posts

And I have one question. In the blog it mentions that X-Forwarded-For also lists proxy IP addresses through whom the response will be forwarded through until it reaches the intranet client. If so can’t this vulnerability be fixed if the web server also has a whitelist of proxy server IPs? After all these proxy servers too are owned by the organization. With that in place, can this setup be exploited in any way or is it as secure as password based authentication?

Thursday 2 June 2022, 18:07  #12
Web - Server HTTP - IP restriction bypass
PriiX
  • 2 posts

I have a question, I’ve done all that you said but I’ve some troubles with the method 2 on Medium’s blog (it doesn’t work on my burp suite). So do can I solve this challenge with the first method and what IP I need to use because the localhost IP doesn’t work.

Thursday 7 July 2022, 06:37  #13
Web - Server HTTP - IP restriction bypass
rickroll
  • 1 posts

new guy here, i submitted my username and password and it says i cant log in for some reason. not sure what they mean by local IP. do they mean, and ip located at their business? Not sure exactly what to do