EFForg/rayhunter

Another indicator of IMSI catcher activity (compare public IP with announced IP ranges)

开放

#153 创建于 2025年3月12日

 (7 条评论) (2 个反应) (1 位负责人)Rust (466 个派生)github user discovery
Research Questionshelp wantedheuristic

仓库指标

星标
 (5,549 个星标)
PR 合并指标
 (平均合并 5天 12小时) (30 天内合并 6 个 PR)

描述

There is an app, called Wiretap Detector that compares your public IP with the announced IP ranges of the mobile operator (of course, you should not be using VPN).

It is using ip.guide service.

With wget, you can get:

  • ASN organization: wget -qO- ip.guide | grep -E 'organization' | sed -E 's/.*"([^"]+)".*/\1/'
  • country: wget -qO- ip.guide | grep -E 'country' | sed -E 's/.*"([^"]+)".*/\1/'
  • your public IP address: wget -qO- ip.guide | grep -E 'ip' | sed -E 's/.*"([^"]+)".*/\1/'
  • ASN number of your network: wget -qO- ip.guide | grep -oP '"asn":\s*\K\d+'

Storing and comparing those data when there is some suspicious network change/activity, would be useful.

贡献者指南