3 ms·
The following can be done for free without an API key or Shodan account: 1. Grab the list of IPs that you've already identified and feed them through nrich (ht
by achillean 4y ago
The following can be done for free without an API key or Shodan account:
1. Grab the list of IPs that you've already identified and feed them through nrich (https://gitlab.com/shodan-public/nrich https://gitlab.com/shodan-public/nrich): "nrich bad-ips.txt"
2. See if all of the offending IPs share a common open port/ service/ provider/ hostname/ etc. Your regular visitors probably connect from IPs that don't have any open ports exposed to the Internet (or just 7547).
3. If the IPs share a fingerprint then you could lazily enrich client IPs using https://internetdb.shodan.io https://internetdb.shodan.io and block them in near real-time. You could also do the IP enrichment before returning content but then you're adding some latency (<40ms) to every page load which isn't ideal.