1.发现

1.1打开题目地址,结合提示,可能与X-Forwarded-For有关。

[BJDCTF2020]The mystery of ip 1_csdn博客

[BJDCTF2020]The mystery of ip 1_csdn博客_02

 1.2修改X-Forwarded-For内容,发现可控。

[BJDCTF2020]The mystery of ip 1_csdn博客_03

 

 2.步骤

2.1修改再次修改X-Forwarded-For。

[BJDCTF2020]The mystery of ip 1_csdn博客_04