9 comments

  • rckoepke 1 hour ago
    In my testing, Synthient's tool[0] and offerings have performed very well for this kind of service. Synthient have also achieved impressive proven success against malicious botnets[1].

    0: https://synthient.com/context/ip/

    1: https://www.wsj.com/tech/kimwolf-hack-residential-proxy-netw... / https://archive.ph/SpKVn

  • jasonvorhe 20 minutes ago
    This would probably false positive every CGNAT IP, or am I misunderstanding something?
  • ranger_danger 1 hour ago
    Keep in mind these databases can be wildly inaccurate and basically impossible to prove them wrong (you can't prove a negative).

    I've seen this (and verified with others) with other sites like iknowwhatyoudownload.com where they allege your connection downloaded something very illegal (like CSAM) even though you know for certain it never happened and you haven't been hacked.

  • varispeed 2 hours ago
    I am on mobile network and it fails to consider this as a factor that other people who might receive this IP could be having a proxy.
    • specproc 42 minutes ago
      Yeah, clicked from my mobile network without thinking and nearly jumped out my skin.
      • microcode 37 minutes ago
        I added a warning that should help with this now.
    • Aurornis 2 hours ago
      If the IP address you're using has been detected as a residential proxy, it doesn't matter. It's going to be flagged on lists for a long time.

      Being able to check is helpful.

      • TacticalCoder 1 hour ago
        > If the IP address you're using has been detected as a residential proxy, it doesn't matter. It's going to be flagged on lists for a long time.

        Flagged and then... What exactly?

        If people who have a smart TV have their smart TV participate in a residential proxy, then it's billions of IP getting "flagged".

        What's the use of flagging those?

        When every IP is flagged, none is.

        • TZubiri 22 minutes ago
          >If people who have a smart TV have their smart TV participate in a residential proxy, then it's billions of IP getting "flagged".

          There's a non-trivial quantity error here that makes the argument of a majority qualitatively incorrect.

          It's not billions of IPs that are being used in residential proxies, it's not all smart TVs.

          There needs to be a vulnerability and hacked devices OR there needs to be a very low quality and shady vendor that is offering products at too cheap prices and needs to make ends meet in order to compete at that price. Probably chinese.

          This would be in the range of 1 to 100 million smart TVs. sorry for the wide range, but definitely not 1Billion or every TV.

          So to the extent that the ratio of infected to non infected IPs is low, then providers can block the infected ones to a great effect.

        • ranger_danger 1 hour ago
          I assume that eventually the flag will just become meaningless and there will be other methods of verification in use by then... because cutting off a huge chunk of your customers just isn't good business.

          But for now I'm already cut off from half the internet due to endless crimeflare captcha loops... I just don't visit those sites anymore because I literally can't.

    • TZubiri 39 minutes ago
      But whether your IP address is being used as a residential proxy is already important information. It answers the question (is this IP address low quality?)

      Although I'll grant that it would be interesting to know if your devices are running the proxy, but you'll need an exeuctable tool for that, not a per-ip network tool.

  • xyst 1 hour ago
    Seems it only detects ipv4. Any plan to support scanning ipv6 /56 range?
  • stogot 2 hours ago
    It says I was observed on a couple areas, but not sure what to do with that information. It would be great if thi tool provided links to guides to discover more.
    • microcode 1 hour ago
      Which proxy network(s) did you get tagged in?
  • toomuchtodo 4 hours ago
    Needs an API to query other IPs beyond one's own.
    • microcode 4 hours ago
      Try https://spur.us/context/<ip> where <ip> is the IP you want to query :)
      • toomuchtodo 4 hours ago
        Thanks! Do you plan on a paid plan? Would you be able to provide methodology under NDA if needed?

        (cyber consultant, have people who might use this for enrichment in security stacks)

        • TZubiri 36 minutes ago
          +1

          Some info on methodology would be necessary for a paid plan for two purposes, one to audit that the quality of the methodology and the signal is good (it's not hallucinated or checking few sources).

          But also to make sure it doesn't clash with other signals if used in conjunction with other sources of tool (if I have another signal, I want to know whether they are redundant or complementary, to avoid interpreting two positives as independently verified.

  • TZubiri 41 minutes ago
    very nice.

    Can we use it in other IPs? (without having to issue the request from that IP)

    • microcode 40 minutes ago
      Yes. You can use https://spur.us/context/<ip> where the IP is the one you want to lookup.