I'm looking at traffic from some of our Chinese customers and their X-Forwarded-For's look something like:
REALIP, 127.0.0.1, REALIP, etc
The interesting thing is the loopback IP is always the second IP address in the list. This implies the connection is going from workstation -> proxy -> proxy on the same host -> another proxy.
This implies that the traffic is going through a proxy on a local machine somewhere.
Is this the Great Firewall? I always figured it would be a transparent proxy. Something else? Has anyone seen this before?
Thanks.