BEWARE - Proxy Detector Script - used by several sites

Latest Status:

Major Proxy Checker Tools are completed. New additions:
- Map
2vmattc.png


- 5 Proxy IP addresses/port checker
(Entered IP addresses/ports as shown below)
fdy150.png

(Note: the process takes up to 2-3 minutes for all 5 proxies)

(Final Result)
dpd7vt.png


In progress:
- ActionScript/Java (that needs bit more work), everything is working great.
- Few other goodies on request by others.

Enjoy this free tool.
 
On the flash cookies - I wrote a simple .sh script a long time ago that would wipe all caches and cookies, when ever I stopped surfing the web.

It's become such a habit that when I close my browser, I start my terminal and just press the up arrow key, then hit the enter button and everything is removed.

@portalweb - are you planning on releasing/selling the proxy checker tool?
 
@savvypro - I never thought about selling my proxy checker tool/system. I developed it to understand how the proxy detection script used by large companies (such as Google, etc.) can be used against the proxy users out there.

Also, this site is developed on the request from my private client and also out of my curiosity. Also, I learned that other "free proxy list" and paid proxy sites rely on cumbersome methods to filter out the proxy IP addresses to meet their needs.

You know, Scrapebox has the proxy checker tool (which I have it), but it's designed for Scrapebox, regardless of where the IP addresses are located from. Same for ProxyFirewall (sort of), too.

This geo-location multi-IP proxy tool has solved many problems they faced when trying to get more details about the proxy IP addresses it uses. That is the reason why I limited the multi-proxy check to 5 items. I use it very often - which works pretty well.

This site is getting nice traffic (2,000-8,000 visitors/day) since the release without any advertisements. If well-marketed, this site would go viral big time.
 
it's funny:) but this is the first good thread what I reading here...and that's the point when a forum turn into real balckhat forum..... I read some good idea in this thread but guys you are on a wrong way:) fisrt: bigger sites hire the best network specialsts and programers... second it seems to me in this forum most people doesn't understand the basics... and they trying to cheat these sites... java applet seems to a good idea, but what happening if I disable java or or I change my mac address:) flash cookies only problem for a noob...

first you guys have to understand these sites want to create an affordable and safety site...and their programers exactly know what are they doing... if you are enough good you will figure out how the things working otherwise you will lose... but need a good knowledge if you want to be sucess...
 
it's funny:) but this is the first good thread what I reading here...and that's the point when a forum turn into real balckhat forum..... I read some good idea in this thread but guys you are on a wrong way:) fisrt: bigger sites hire the best network specialsts and programers...

That is why this topic is created for this purpose - to understand how they are using their own in-house backend proxy detector scripts to detect the proxy users.

There's always a way to bypass the proxy detection script - by using the high quality filtered proxy IP address, running on well-configured proxy server. That is where I'm looking into it shortly.

second it seems to me in this forum most people doesn't understand the basics... and they trying to cheat these sites... java applet seems to a good idea, but what happening if I disable java or or I change my mac address:) flash cookies only problem for a noob...
Not many sites are using Java (except for popular online games, such as Yahoo games). I can disable Java services (see my earlier post here) anytime if I want to as I do not see the reason for it (except for the proxy detection tool development here). As for the Flash (using ActionScript), I believe it will be on downhill trend, thanks to Apple's refusal of using Flash for iPad, as well as the phase in of the HTML5 that will display native videos (using Ogg format - see hxxp://en.wikipedia.org/wiki/HTML5_video for details). Both ActionScript and Java can read the computer network interface details directly, which is considered as very scary intrusion attempt by the proxy detection scripts used by big sites. That is the reason why I disabled both services most of the time.

first you guys have to understand these sites want to create an affordable and safety site...and their programers exactly know what are they doing... if you are enough good you will figure out how the things working otherwise you will lose... but need a good knowledge if you want to be sucess...

I already figured out on how they are looking at proxy users, thanks to this proxy tool I developed. You are correct about the programmers (if they are good ;) ). Of course, we are living in the world of cat and mouse game, which will never end.
 
Here's the warning from Tor site about revealing the IP address:
Code:
http://www.torproject.org/download.html.en#Warning

Torbutton blocks browser plugins such as Java, Flash, ActiveX, RealPlayer, Quicktime, Adobe's PDF plugin, and others: they can be manipulated into revealing your IP address.
For example, that means Youtube is disabled. If you really need your Youtube, you can reconfigure Torbutton to allow it; but be aware that you're opening yourself up to potential attack. Also, extensions like Google toolbar look up more information about the websites you type in: they may bypass Tor and/or broadcast sensitive information. Some people prefer using two browsers (one for Tor, one for unsafe browsing).

I think this Torbutton for Firefox is perfect for noobies.
Code:
https://addons.mozilla.org/en-US/firefox/addon/2275

Hope it helps.
 
Of course, we are living in the world of cat and mouse game, which will never end.


this is the key always bring information and testing and testing and thinking
 
Hello

I want to thank all of you for the valuable information shared in this post. I was checking "whoer" site and they always find out the real IP I use private proxies I try some of them and always show my real IP then I try a VPN service this time they didn't find my IP it shows the VPN's IP but they found my DNS I also try VPN with private proxies and always shows my DNS I installed noscripts pluggins for Firefox and obviously it stop whatever script they are running but the thing is if you want access to those websites you have to let them run those scripts otherwise they won't let you pass. By the way before the test u ran ccleaner to make sure I was clean.

My question is. Is there a way to trick those scripts and give them wrong info?
 
I check'd few proxy on whatismyip.....

below is result of free anonymous socks5 scan


2rc2682.jpg


i scanned same ip atleast 4 times ..result came up all wid false but it still says proxy detect..can anyone explain me dis ?
on home page it says
Connection: http://whatismyipaddress.com/broadband Assignment: http://whatismyipaddress.com/dynamic-static Proxy: Suspected Network Sharing Device

now below is result of private socks5

jr79jm.jpg


the site doesnt detect private socks (as few user already mentioned in post )

@ superseguro


whoer site caught me

same with me bro ...on mah VPS ...it detected mah private proxy and mah VPS dns

here is result
IP address 171.128.122.186
http://whoer.net/ext# binary 10101110 01111011 01110001 10111010 decimal 2927325626 octal 0256 0173 0161 0272 hexidecimal AE 7B 71 BA
Hostname ba.71.7bae.static.thenet.com → N/A Mail server mx01.thenet.com IP range .0.255.255 ISP THENET.COM INTERNET SERVICES Organization THENET.COM INTERNET SERVICES Black list No Proxy

under Interactive detection

it shows mah proxy and VPS IP both...


do you guyz think gtp and get paid to download sites got this kind of script ?:rolleyes:...I dont wanna get ban :madfawk:....please help this noob ..lolz
 
Last edited:
Hi,

I want to let you know about this one:

Code:
http://en.wikipedia.org/wiki/User:ProcseeBot
This site detects the major types of proxies automatically (even elites), which will prevent anyone from editing the wikipedia page. I know about it for a while - but I never expect that their proxy detection is much better now than before.

I ran the back-end tests and noticed that if your proxy IP address (even it's elite), Wikipedia will report it as proxy. Then, I made the comparison with other elite proxy IP addresses, which I use it as a reference (to tell which one are detected), which I noticed their ProcceeBot proxy detection tool has been improved.

Their proxy detection system is similar to this site:
Code:
[URL]http://whatismyipaddress.com/staticpages/index.php/advanced-proxy-test[/URL]
Oh well. :)

Note: My site is currently off-line (available for private users only on request). Reason: Huge traffic coming from China/Asia/Middle East, which is not very good, as well as wasting my bandwidth.
 
Hi,

I want to test to see how they can detect the proxy IP, by going to this site:

WIMIA Test TRUE


Where can I get the software to do a Wimia test. I have have one problem user on my website who just does not get the message that he is not weclome, and just looks for another proxy, when he is banned. A Wimia test would solve the problem? Where can I get the software I need to implement Wimia on my web site?
 
VPNS can be detected too, I have tested this with VPNs and it can be detected.

Yes and no.

We have experimented on different VPNs from various VPN providers with the assistance from private clients.

Because of that, I have the "special configured elite" VPNs running on my servers for my private clients, and yes, they are undetectable. Yes, My special VPNs can access to online banks, Paypal, and other high-end sites without any detection.

"Low-end" VPN providers with basic/badly configured VPN services are not truly anonymous, which can be easily detectable.

http://analyzemy.net is what I used for testing the proxies (and VPNs, too).

Hope it helps. :)
 
The following code has been used to fool the "dreaded" WIMIA Test:

// java's thread for a home-grown proxy
// incomingSoc: request coming from your browser
// outgoingSoc: webHost where the request is sent to... :mrgreen:
try {
InputStream iis = incomingSoc.getInputStream();
StringBuffer buf = new StringBuffer();
while (buf.lastIndexOf("\r\n\r\n") < 0 && (b = iis.read()) != -1) buf.append((char) b);
b = Math.abs((new Random()).nextInt());
// fake the USER_AGENT, here you faked the USER_AGENT from a predefined array :P with a random index b
int l = buf.indexOf("User-Agent:") ;
buf.replace(l, buf.indexOf("\r\n", l), fakedUserAgent);
// kill outgoing Cookies, fool the IP-snooper (
buf.insert(buf.lastIndexOf("\r\n\r\n"), "\r\nX-Forwarded-For: "+ fakedIP);
if (cp.outCookies) while ((b = buf.indexOf("Cookie:")) > 0) buf.delete(b, buf.indexOf("\r\n", b)+2);
...
OutputStream oos = outgingSoc.getOutputStream();
oos.write(buf.toString().getbytes());
...
 
Back
Top