Ross ROSS = Recommend OSS · open-source software intelligence for agents

TheKingOfDuck/burpFakeIP

服务端配置错误情况下用于伪造ip地址进行测试的Burp Suite插件 observed · 2026-08-28

github.com/TheKingOfDuck/burpFakeIP · Java observed · 2026-08-28

Health v2 · maintenance only

23/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2646
  • days_rel: n/a
  • days_push: 1434
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1668 stars · 231 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A Burp Suite extension written in Java that forges IP addresses in HTTP request headers (X-Forwarded-For and similar) to test servers with misconfigured IP-based access controls. It supports spoofing specific, local, or random IPs and integrating random IP payloads into Intruder attacks.

Use cases

  • bypass ip-based rate limiting in burp intruder
  • test server for x-forwarded-for spoofing vulnerabilities
  • forge client ip in http requests during pentest
  • rotate random fake ips while brute forcing
  • check if server trusts spoofed ip headers

When to choose

  • you use Burp Suite and need to test IP header spoofing or rate-limit bypasses
  • you want automatic XFF header injection with random IPs across requests

When to avoid

  • the target correctly derives client IP from the socket rather than headers
  • you need a standalone proxy or non-Burp testing tool

Facets

plugin · maturity maintenance

penetration-testing security http-client security penetration-testing developer-tools jvm burp-suite-extension ip-spoofing x-forwarded-for intruder rate-limit-bypass

1 source

Member repositories

RepositoryRoleHealth v2
TheKingOfDuck/burpFakeIPmain23

For agents

markdown · JSON · MCP: product_card(name="TheKingOfDuck/burpFakeIP")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem