I just started implementing
$ENV{'HTTP_X_FORWARDED_FOR'}
in my logging scripts. It seems very useful to get the original ip from visitors behind a proxy.
I wonder I anybody has been using this in cloaking scripts, and if well known spiders were ever found hiding behind a proxy ?