EFForg / EFForg/rayhunter

Another indicator of IMSI catcher activity (compare public IP with announced IP ranges)

Open
#153 7 comments 2 reactions 1 assignee Claimed by @cooperq View on GitHub
help wanted heuristic Research Questions
Dominant language
Rust
Stars
5.8k
Forks
490
Avg merge
3d 10h
Merged PRs (30d)
23

Description

There is an app, called [Wiretap Detector](https://github.com/Glamdring/wiretap-detector) that compares your public IP with the announced IP ranges of the mobile operator (of course, you should not be using VPN).

It is using `ip.guide` service.

With wget, you can get:
- ASN organization: `wget -qO- ip.guide | grep -E 'organization' | sed -E 's/.*"([^"]+)".*/\1/'`
- country: `wget -qO- ip.guide | grep -E 'country' | sed -E 's/.*"([^"]+)".*/\1/'`
- your public IP address: `wget -qO- ip.guide | grep -E 'ip' | sed -E 's/.*"([^"]+)".*/\1/'`
- ASN number of your network: `wget -qO- ip.guide | grep -oP '"asn":\s*\K\d+'`

Storing and comparing those data when there is some suspicious network change/activity, would be useful.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.