A service's rate limiter reads `X-Forwarded-For` from every incoming request and blocks abusive IPs by that value. An attacker gets around it easily. What's the actual mistake, and what should the rate limiter read instead?
X-Forwarded-For is a request header, which means the client sending the original request controls its initial value completely — an attacker can simply set X-Forwarded-For: 1.2.3.4 themselves and the service, reading the header naively, believes whatever the attacker claimed. The header only becomes trustworthy at the point a proxy the service actually controls appends the real connecting client's address to it, which means the only part of the header's value that can be trusted is the entry the trusted proxy itself added — the last one, not the first. Trusting the first entry (which is exactly what the attacker controls) defeats the whole point of the check; trusting the last entry — the one nginx appended — is what a rate limiter actually needs to read, alongside X-Real-IP, which nginx sets to the single real connecting address and cannot be spoofed by the client because nginx overwrites it regardless of what the client sent.