CompTIA CySA+ (CS0-003)Security OperationsMedium

A security analyst is performing a penetration test against a web application. During the reconnaissance phase, the analyst discovers that the application uses a reverse proxy. To bypass IP-based access restrictions and potentially spoof their origin, the analyst modifies HTTP headers. Which HTTP header is commonly abused for this purpose?

  1. AContent-Type
  2. BX-Forwarded-For
  3. CReferer
  4. DUser-Agent
Show answer & explanation

Correct answer: B. X-Forwarded-For

The `X-Forwarded-For` header is a de-facto standard for identifying the originating IP address of a client connecting to a web server through an HTTP proxy or load balancer. Attackers can manipulate this header to spoof their IP address, potentially bypassing IP-based access controls or logging mechanisms that rely on this header for source identification.

Why the other options are wrong

  • A. Content-Type specifies the media type of the resource, not the client's IP address.
  • C. Referer indicates the URL of the page that linked to the current request, not the client's IP address.
  • D. User-Agent identifies the client's browser or application, not its originating IP.

X-Forwarded-For Header Abuse

Exploiting the X-Forwarded-For HTTP header, which identifies the client's originating IP when behind a proxy, by manipulating it to spoof the source IP address.

  • Used to bypass IP-based access controls (e.g., allow-lists).
  • Can obscure the true attacker IP in logs.
  • Requires the web application to trust this header for IP identification.

Memory trick: Headers can hide or reveal the truth.

More Security Operations questions