3 ms·
If you're seeing connections from random residential IPs, they're probably using a reverse-proxy service like Luminati or 911.re. IP blocklists won't catch thes
by kbuck 6y ago
If you're seeing connections from random residential IPs, they're probably using a reverse-proxy service like Luminati or 911.re. IP blocklists won't catch these. These proxies originate from (basically) compromised computers -- people who install "free" browser extensions and the like: https://www.trendmicro.com/vinfo/hk-en/security/news/cybercrime-and-digital-threats/shining-a-light-on-the-risks-of-holavpn-and-luminati https://www.trendmicro.com/vinfo/hk-en/security/news/cybercr...
With a troll this persistent (and willing to spend money on it), your best bet is definitely shadow bans and moderation queues.
- ev1 6y agoIt isn't just random residential IPs, but what appears to be BGP hijacking of/onto residential networks on top of that.
- bawolff 6y agoWhat's the basis for assuming BGP hijacking? That would be very sophisticated attack to just troll some random website.
- ev1 6y agoThe skid is not the one doing it. They are buying from semi-professional "proxy sellers" that do it and then sell you some form of authenticated squid proxy that further makes the request.
- GoblinSlayer 6y agoCan't he fake the source IP address by sending raw packets? Are they sanitized in any way?
- dnet 6y agoThat wouldn't work for HTTP(S) or anything else that works over TCP since the reply would go towards the fake source IP address, thus the attacker couldn't even get past the 3-way TCP handshake.
- stickfigure 6y agoCan you elaborate? If the troll is using residential proxies, you might try abuse@ the handful of services that offer such things. There aren't that many. I don't know if they actually take abuse seriously, but it can't hurt. Luminati has an abuse form: https://luminati.io/report-abuse https://luminati.io/report-abuse