Wikipedia:Open proxies noticeboard/Requests
![]() | Looking to make a new report? You're in the wrong place! Please go to Wikipedia:Open proxies noticeboard#Reporting and fill in the relevant box. |
Index |
This page has archives. Sections older than 41666.5 days may be automatically archived by ClueBot III when more than 5 sections are present. |
119.231.70.144
[edit] – This proxy check request is closed and will soon be archived by a bot.
- 119.231.70.144 · talk · contribs · block · log · stalk · Robtex · whois · Google · ipcheck · HTTP · geo · rangeblocks · spur · shodan
Reason: Vandalizing USSR anti-religious campaign (1958–1964). jlwoodwa (talk) 20:03, 28 April 2025 (UTC)
Open proxy blocked as part of VPN Gate. — Naomi Amethyst 07:25, 30 April 2025 (UTC)
59.187.201.43
[edit] – This proxy check request is closed and will soon be archived by a bot.
- 59.187.201.43 · talk · contribs · block · log · stalk · Robtex · whois · Google · ipcheck · HTTP · geo · rangeblocks · spur · shodan
Reason: Vandalizing USSR anti-religious campaign (1958–1964). jlwoodwa (talk) 20:22, 28 April 2025 (UTC)
Open proxy blocked as part of VPN Gate. — Naomi Amethyst 07:25, 30 April 2025 (UTC)
42.114.80.68
[edit] – This proxy check request is closed and will soon be archived by a bot.
- 42.114.80.68 · talk · contribs · block · log · stalk · Robtex · whois · Google · ipcheck · HTTP · geo · rangeblocks · spur · shodan
Reason: Vandalizing KGB. jlwoodwa (talk) 23:03, 28 April 2025 (UTC)
Open proxy blocked as part of VPN Gate. — Naomi Amethyst 07:26, 30 April 2025 (UTC)
38.158.220.26
[edit] – This proxy check request is closed and will soon be archived by a bot.
- 38.158.220.26 · talk · contribs · block · log · stalk · Robtex · whois · Google · ipcheck · HTTP · geo · rangeblocks · spur · shodan
Reason: Block evasion, see SPI. Tule-hog (talk) 17:06, 7 May 2025 (UTC)
Open proxy blocked — Naomi Amethyst 22:56, 7 May 2025 (UTC)
195.82.104.0/23
[edit] – This proxy check request is closed and will soon be archived by a bot.
This is a rangeblock for a datacentre, AS43160, but it doesn't look like that's accurate anymore. Got here via an unblock request for 195.82.104.57, which is currently showing as AS200845. Would appreciate if someone could double-check this and unblock as appropriate. asilvering (talk) 21:41, 7 May 2025 (UTC)
- You are correct that the ASN has changed and it looks like the range is now owned by a different company, but there's definitely some hosting still going on there, even on the individual IP address. It's the webhost for iberofurs, for example:
Nmap scan report for 57.104.82.195-avatel.es (195.82.104.57) Host is up, received user-set (0.12s latency). Scanned at 2025-05-07 23:03:17 UTC for 174s Not shown: 65534 filtered tcp ports (no-response) PORT STATE SERVICE REASON VERSION 80/tcp open http syn-ack ttl 49 Apache httpd 2.4.62 | http-robots.txt: 1 disallowed entry |_/wp-admin/ |_http-title: iberofurs |_http-generator: WordPress 6.8.1 |_http-server-header: Apache/2.4.62 (Debian) | http-methods: |_ Supported Methods: GET HEAD POST OPTIONS 443/tcp open ssl/http syn-ack ttl 49 Apache httpd 2.4.62 ((Debian)) |_http-server-header: Apache/2.4.62 (Debian) |_ssl-date: TLS randomness does not represent time |_http-generator: WordPress 6.8.1 | ssl-cert: Subject: commonName=iberofurs.org | Subject Alternative Name: DNS:iberofurs.org, DNS:www.iberofurs.org | Issuer: commonName=E6/organizationName=Let's Encrypt/countryName=US | Public Key type: ec | Public Key bits: 256 | Signature Algorithm: ecdsa-with-SHA384 | Not valid before: 2025-04-03T18:14:39 | Not valid after: 2025-07-02T18:14:38 | MD5: 5b1e:fe2b:92bf:6a26:101f:0675:ca7b:7bc5 | SHA-1: 1d3a:f34d:6436:797c:1fd6:eed9:0078:6430:7fc3:4d12 | -----BEGIN CERTIFICATE----- | MIIDvjCCA0OgAwIBAgISBZV+b1B69qEFgiNr7zvjsOAbMAoGCCqGSM49BAMDMDIx | CzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQswCQYDVQQDEwJF | NjAeFw0yNTA0MDMxODE0MzlaFw0yNTA3MDIxODE0MzhaMBgxFjAUBgNVBAMTDWli | ZXJvZnVycy5vcmcwWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAARI7C+HnTaP/srV | tbdnAjPeJ95IsSbKlZayq7pSFy1o5tua/+Je8Kmson/pMVvNafl/yVaC4mo8+JW3 | AtyfAtMQo4ICUTCCAk0wDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUF | BwMBBggrBgEFBQcDAjAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBSXgd83GxuSTYlA | SFmuASnHpaLNCTAfBgNVHSMEGDAWgBSTJ0aYA6lRaI6Y1sRCSNsjv1iU0jBVBggr | BgEFBQcBAQRJMEcwIQYIKwYBBQUHMAGGFWh0dHA6Ly9lNi5vLmxlbmNyLm9yZzAi | BggrBgEFBQcwAoYWaHR0cDovL2U2LmkubGVuY3Iub3JnLzArBgNVHREEJDAigg1p | YmVyb2Z1cnMub3JnghF3d3cuaWJlcm9mdXJzLm9yZzATBgNVHSAEDDAKMAgGBmeB | DAECATAtBgNVHR8EJjAkMCKgIKAehhxodHRwOi8vZTYuYy5sZW5jci5vcmcvMjgu | Y3JsMIIBBAYKKwYBBAHWeQIEAgSB9QSB8gDwAHYAEvFONL1TckyEBhnDjz96E/jn | tWKHiJxtMAWE6+WGJjoAAAGV/RJKcAAABAMARzBFAiBC+RoBgVWxiS2fHGyHMek1 | U4+VW8aJGw1KGZ1xCEt7NgIhAMomMLKrsQJ0i9d+EYebooaS+J28MbVuULYaAgw6 | 2Y2uAHYA7TxL1ugGwqSiAFfbyyTiOAHfUS/txIbFcA8g3bc+P+AAAAGV/RJSQwAA | BAMARzBFAiAoJqmO9ShA9Oa8ZTGgGOApnwhz4tjzhycBEqFgNHY7MwIhAIh7aKEl | /aW5nIlgDMD0FkhIegj2C4xcmKi8BArRkpaJMAoGCCqGSM49BAMDA2kAMGYCMQDU | VL5MFVIveATU1xB31mYGVs5GYSlldHCQGrDpZ6g+U3GX6rxpnQrJXJ9CpWeQy2cC | MQDTwxX6tWoeFtRNsFmMguEwLJYfTgBraNU0JASzGkn32LLDfhkQ6aw+oe09hr60 | q8I= |_-----END CERTIFICATE----- |_http-title: iberofurs | http-methods: |_ Supported Methods: GET HEAD POST OPTIONS | http-robots.txt: 1 disallowed entry |_/wp-admin/ Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port OS fingerprint not ideal because: Missing a closed TCP port so results incomplete No OS matches for host TCP/IP fingerprint: SCAN(V=7.94SVN%E=4%D=5/7%OT=80%CT=%CU=%PV=N%DS=14%DC=T%G=N%TM=681BE763%P=x86_64-pc-linux-gnu) SEQ(SP=107%GCD=1%ISR=10B%TI=Z%II=I%TS=A) OPS(O1=M584ST11NW7%O2=M584ST11NW7%O3=M584NNT11NW7%O4=M584ST11NW7%O5=M584ST11NW7%O6=M584ST11) WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=FE88) ECN(R=Y%DF=Y%TG=40%W=FAF0%O=M584NNSNW7%CC=Y%Q=) T1(R=Y%DF=Y%TG=40%S=O%A=S+%F=AS%RD=0%Q=) T2(R=N) T3(R=N) T4(R=N) U1(R=N) IE(R=Y%DFI=N%TG=40%CD=S) Uptime guess: 2.371 days (since Mon May 5 14:11:29 2025) Network Distance: 14 hops TCP Sequence Prediction: Difficulty=263 (Good luck!) IP ID Sequence Generation: All zeros Service Info: Host: iberofurs.org TRACEROUTE (using port 443/tcp) HOP RTT ADDRESS 1 0.96 ms _gateway (10.199.22.3) 2 0.46 ms rtr-ge-dmarc.tblflp.net (10.199.1.1) 3 ... 4 3.94 ms rcmt-agw1.inet.qwest.net (71.32.31.17) 5 19.69 ms 4.68.144.73 6 11.95 ms 1299-3356-wdc.sp.lumen.tech (4.68.111.150) 7 11.98 ms ash-bb2-link.ip.twelve99.net (62.115.123.124) 8 ... 9 110.19 ms mad-b3-link.ip.twelve99.net (62.115.123.219) 10 108.39 ms avateltelecom-ic-374237.ip.twelve99-cust.net (62.115.172.69) 11 ... 13 14 124.00 ms 57.104.82.195-avatel.es (195.82.104.57)
- Also 195.82.104.28 has a Watchguard device, 195.82.104.2 has a webcam, and the list goes on and on. The range is too big to do an in-depth test of each, but it is very
Likely IP is an open proxy — Naomi Amethyst 23:14, 7 May 2025 (UTC)
- Alas for this blocked editor. Thanks for the double-check. -- asilvering (talk) 23:24, 7 May 2025 (UTC)
- Wait, I think that website is them, actually. UTRS appeal #102938 is the relevant appeal. -- asilvering (talk) 23:33, 7 May 2025 (UTC)
- Ahh, good point, that ticket adds some context. The range still seems suspicious, and I'll do some more digging later today — especially as I didn't find anything conclusive, just likely in the range. I've marked this request
Reopened for now. — Naomi Amethyst 12:09, 8 May 2025 (UTC)
- @Asilvering: I went ahead and dug deeper into this range, and didn't find any obvious open proxies. While it has a ton of open ports and hosting things, on deeper investigation, it appears like it is a business/residential ISP range (as the WHOIS says) that the ISP uses for people who request static IPs, and so has a bunch of IP cameras, NASs, and self-hosted things. As such, I've unblocked the range. I would caution the appellant that even though the block has been removed, editing or creating pages about their own ventures needs to follow the WP:COI policies. — Naomi Amethyst 21:03, 11 May 2025 (UTC)
- Ahh, good point, that ticket adds some context. The range still seems suspicious, and I'll do some more digging later today — especially as I didn't find anything conclusive, just likely in the range. I've marked this request
- Wait, I think that website is them, actually. UTRS appeal #102938 is the relevant appeal. -- asilvering (talk) 23:33, 7 May 2025 (UTC)
- Alas for this blocked editor. Thanks for the double-check. -- asilvering (talk) 23:24, 7 May 2025 (UTC)
Completed — Naomi Amethyst 21:03, 11 May 2025 (UTC)
IP
[edit] A user has requested a proxy check. A proxy checker will shortly look into the case.
- 115.167.65.218 · talk · contribs · block · log · stalk · Robtex · whois · Google · ipcheck · HTTP · geo · rangeblocks · spur · shodan
Flagged as an open-proxy by whatsmyip, abused by an LTA that mostly uses open proxies (he won't use it again, but others might), and already blocked as an open proxy an zh-wiki. Seems pretty straightforward to me. 184.152.65.118 (talk) 00:20, 16 May 2025 (UTC)