Live data from Hacker News

API providing threat analysis of any given IP address

fraudguard.io

11–20 of 84 posts

Re: API providing threat analysis of any given IP address

#11
"Our Team of Engineers track public IPs across a wide scope of popular botnet networks."

How do you track botnets (along with the other collection you do) with a team of three? How many botnets are being tracked and which malware families? This is an especially dubious claim when coupled with another statement you made: "We do not rely on external sources at this time".

Re: API providing threat analysis of any given IP address

#13
post #12

I operate two non-exit tor relays. They have both return risk_level: 4 with the "threat" being "tor_tracker". What threat is posed by a non-exit tor relay? What does the "tracker" part of "tor_tracker" mean?

Not sure, but I've been put on an IP banlist for simply operating a non-exit relay in the past. Had to switch my home IP. The myth that is perpetuated that if you run a non-exit relay that you'll have no problems with IP bans is definitely wrong.

Re: API providing threat analysis of any given IP address

#15

Correction, API providing: 502 Bad Gateway nginx/1.8.1

Ya, I'm the idiot that went to Chipotle in the middle of a launch. Haha

No excuse! ;)

(I love this spirit of this project. If you have any way others can contribute, I would be interested!)

Re: API providing threat analysis of any given IP address

#17

"Our Team of Engineers track public IPs across a wide scope of popular botnet networks." How do you track botnets (along with the other collection you do) with a team of three? How many botnets are being tracked and which malware families? This is an especially dubious claim when coupled with another statement you made: "We do not rely on external sources at this time".

I bet he is using maltrail and firehol.

Re: API providing threat analysis of any given IP address

#19
post #17

"Our Team of Engineers track public IPs across a wide scope of popular botnet networks." How do you track botnets (along with the other collection you do) with a team of three? How many botnets are being tracked and which malware families? This is an especially dubious claim when coupled with another statement you made: "We do not rely on external sources at this time".

I bet he is using maltrail and firehol.

We do use Maltrail along with a whole lot else. You don't have experience with it perhaps? Are you currently employed or angry at your employer?
Post reply on HN