RE: Integrating with webserver
"Ryan White" <[email protected]>
| Newsgroups | gmane.network.irc.bopm |
|---|---|
| Message-ID | <[email protected]> |
I thought of that. The thing is that I used one of the fraud IP's and it did not show up in the blacklists. I can't afford that. I am planning on checking the blacklists first then scanning. If possible reporting back the blacklists with open proxies. Mind you this is only for our merchant processing page. This is not the main page of the site or anything. -Ryan -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of Andy Smith Sent: Monday, February 16, 2004 11:41 AM To: [email protected] Subject: Re: [bopm] Integrating with webserver On Mon, Feb 16, 2004 at 11:14:00AM +0000, David Leadbeater wrote: > Ryan White wrote: > [...] > > My goal is to use bopm to prevent fraud going to my merchant processor. > > Currently they are too incompetent to do an open proxy scan against > > customer orders. [...] > The scanning part of BOPM is seperated into libopm, this is a C > library and also provides Perl bindings (OPM). See > http://o.dgl.cx/opm-perl-api and also look at > http://cvs.blitzed.org/*checkout*/libopm/doc/libopm-api.txt If I were trying to do the same as this person I would not use libopm at all, but instead just check IPs against many public blacklists of proxies. I would also try to look for indicators of abuse in the system and when it is found, submit those IPs to various public blacklists for scanning. I don't think that every web site on the internet should be testing for proxies. -- Andy Smith -- Occasional BOPM Developer And Support Monkey. Please copy all BOPM support queries to the BOPM list, _not_ just directly to me! If I've helped you with BOPM then please check my wishlist! http://www.amazon.co.uk/exec/obidos/registry/23IJ4U7N4J3X9