|
|
|
|
|
by jeroenhd
174 days ago
|
|
Do raw TCP proxies still get used often? I'd imagine most proxies you'd want to detect are full HTTP proxies and this formula won't detect those. I suppose it's possible botnets ("residential proxies") may get detected this way if they're using SOCKS to forward requests? Still, this looks like an interesting signal to add to a system like Anubis to increase the difficulty for suspicious traffic sources. This does very reliably detect TOR traffic, though you can just download a list of exit nodes if that's what you want. |
|