EFForg/rayhunter

Another indicator of IMSI catcher activity (compare public IP with announced IP ranges)

Aperta

#153 aperta il 12 mar 2025

 (7 commenti) (2 reazioni) (1 assegnatario)Rust (447 fork)github user discovery
Research Questionshelp wantedheuristic

Metriche repository

Star
 (5428 stelle)
Metriche merge PR
 (Merge medio 5g 12h) (6 PR mergiate in 30 g)

Descrizione

There is an app, called Wiretap Detector that compares your public IP with the announced IP ranges of the mobile operator (of course, you should not be using VPN).

It is using ip.guide service.

With wget, you can get:

  • ASN organization: wget -qO- ip.guide | grep -E 'organization' | sed -E 's/.*"([^"]+)".*/\1/'
  • country: wget -qO- ip.guide | grep -E 'country' | sed -E 's/.*"([^"]+)".*/\1/'
  • your public IP address: wget -qO- ip.guide | grep -E 'ip' | sed -E 's/.*"([^"]+)".*/\1/'
  • ASN number of your network: wget -qO- ip.guide | grep -oP '"asn":\s*\K\d+'

Storing and comparing those data when there is some suspicious network change/activity, would be useful.

Guida contributor