Files
felhom.eu/documentation/audits/visitors-2026-10-01/probe.sh
T

12 lines
1019 B
Bash
Executable File

#!/bin/bash
# probe.sh <label> — requests through the REAL tunnel to the echo app: plain, then with forged headers
H=a1-echo.enkisfelhom.hu
F='^(RemoteAddr|X-Forwarded|X-Real|Cf-Connecting|True-Client|Forwarded)'
echo "## $1 — plain, $(date -u +%FT%TZ)"
curl -s --max-time 20 "https://$H/plain-$RANDOM" | grep -iE "$F"
echo "## $1 — forged: XFF 6.6.6.6, X-Real-IP 8.8.4.4, True-Client-IP 9.9.9.9, X-Forwarded-Host evil.example, X-Forwarded-Port 8443, X-Forwarded-Proto http, Forwarded for=5.5.5.5"
curl -s --max-time 20 "https://$H/forged-$RANDOM" -H 'X-Forwarded-For: 6.6.6.6' -H 'X-Real-IP: 8.8.4.4' \
-H 'True-Client-IP: 9.9.9.9' -H 'X-Forwarded-Host: evil.example' -H 'X-Forwarded-Port: 8443' -H 'X-Forwarded-Proto: http' -H 'Forwarded: for=5.5.5.5' \
| grep -iE "$F"
echo "## $1 — forged CF-Connecting-IP 7.7.7.7 alone: HTTP $(curl -s -o /dev/null -w '%{http_code}' --max-time 20 "https://$H/cfci-$RANDOM" -H 'CF-Connecting-IP: 7.7.7.7') (Cloudflare's edge answers; the request never reaches the box)"