Wikipedia:Open proxies noticeboard

    Open proxies noticeboard

    The Open proxies noticeboard seeks to identify, verify and block open proxies and anonymity network exit nodes. To prevent abuse or vandalism, only proxy checks by verified users will be accepted. All users are welcome to discuss on the talk page, report possible proxies, or request that a blocked IP be rechecked.

    • If you've been blocked as an open proxy, please see: Help:blocked.
    • To report a proxy check or an incorrect block, see the #Reporting section.


    Reporting

    Please report IP addresses you suspect are open proxies below. A project member will scan or attempt to connect to the proxy, and if confirmed will block the address.

    File a new report here
    I.
    For block requests:

    Verify that the following criterion has been met:

    • The IP has made abusive contributions within the past week
    For unblock requests:

    Verify that the following criteria has been met:

    • No current criteria
    II.

    For block requests Replace "IP" below with the IP address you are reporting.


    For unblock requests Replace "IP" below with the IP address you are reporting.


    III.Fill out the resulting page and fill-in the requested information.
    IV.Save the page.
    Verified Users/Sysops Templates
    • IP is an open proxy {{Proxycheck|confirmed}} for confirmed open proxies and Tor exit nodes.
    •  Likely IP is an open proxy {{Proxycheck|likely}} for likely open proxies and Tor exit nodes.
    •  Possible IP is an open proxy {{Proxycheck|possible}} for possible open proxies and Tor exit nodes.
    •  Unlikely IP is an open proxy {{Proxycheck|unlikely}} for unlikely open proxies and Tor exit nodes.
    • Not currently an open proxy {{Proxycheck|unrelated}} for IP's confirmed not to be an open proxy or Tor exit node.
    • Inconclusive {{Proxycheck|inconclusive}} for IP's that are inconclusive.
    • no Declined to run a check {{Proxycheck|decline}} to decline a check.
    • Open proxy blocked {{Proxycheck|blocked}} for open proxies and Tor nodes that have been blocked. Please add this if you block the IP.

    Requests


    194.135.119.59

    – This proxy check request is closed and will soon be archived by a bot.

    Reason: Block evasion via proxy. (See reports above.) Tule-hog (talk) 06:06, 22 April 2025 (UTC)[reply]

     Likely IP is an open proxy
    Nmap scan report for 194.135.119.59
    Host is up, received user-set (0.16s latency).
    Scanned at 2025-04-22 06:10:13 UTC for 73s
    
    PORT      STATE    SERVICE          REASON         VERSION
    21/tcp    filtered ftp              no-response
    22/tcp    filtered ssh              no-response
    80/tcp    open     http             syn-ack ttl 51
    |_http-title: ERROR: The requested URL could not be retrieved
    | fingerprint-strings:
    |   GetRequest:
    |     HTTP/1.1 400 Bad Request
    |     mime-version: 1.0
    |     date: Tue, 22 Apr 2025 06:10:21 GMT
    |     content-type: text/html;charset=utf-8
    |     content-length: 3541
    |     vary: Accept-Language
    |     content-language: en
    |     connection: close
    |     <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
    |     <html><head>
    |     <meta type="copyright" content="Copyright (C) 1996-2020 The Squid Software Foundation and contributors">
    |     <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
    |     <title>ERROR: The requested URL could not be retrieved</title>
    |     <style type="text/css"><!--
    |     Copyright (C) 1996-2023 The Squid Software Foundation and contributors
    |     Squid software is distributed under GPLv2+ license and includes
    |     contributions from numerous individuals and organizations.
    |     Please see the COPYING and CONTRIBUTORS files for details.
    |     Stylesheet for Squid Error pages
    |     Adapted
    |   HTTPOptions:
    |     HTTP/1.1 400 Bad Request
    |     mime-version: 1.0
    |     date: Tue, 22 Apr 2025 06:10:22 GMT
    |     content-type: text/html;charset=utf-8
    |     content-length: 3541
    |     vary: Accept-Language
    |     content-language: en
    |     connection: close
    |     <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
    |     <html><head>
    |     <meta type="copyright" content="Copyright (C) 1996-2020 The Squid Software Foundation and contributors">
    |     <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
    |     <title>ERROR: The requested URL could not be retrieved</title>
    |     <style type="text/css"><!--
    |     Copyright (C) 1996-2023 The Squid Software Foundation and contributors
    |     Squid software is distributed under GPLv2+ license and includes
    |     contributions from numerous individuals and organizations.
    |     Please see the COPYING and CONTRIBUTORS files for details.
    |     Stylesheet for Squid Error pages
    |_    Adapted
    443/tcp   open     openvpn          syn-ack ttl 51 OpenVPN
    1080/tcp  filtered socks            no-response
    3182/tcp  filtered bmcpatrolrnvu    no-response
    5000/tcp  filtered upnp             no-response
    8000/tcp  filtered http-alt         no-response
    8080/tcp  open     http-proxy?      syn-ack ttl 51
    8443/tcp  open     https-alt?       syn-ack ttl 51
    8888/tcp  filtered sun-answerbook   no-response
    9050/tcp  filtered tor-socks        no-response
    9150/tcp  filtered unknown          no-response
    10000/tcp filtered snet-sensor-mgmt no-response
    20000/tcp filtered dnp              no-response
    1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
    SF-Port80-TCP:V=7.94SVN%I=7%D=4/22%Time=680732CE%P=x86_64-pc-linux-gnu%r(G
    SF:etRequest,EA6,"HTTP/1\.1\x20400\x20Bad\x20Request\r\nmime-version:\x201
    SF:\.0\r\ndate:\x20Tue,\x2022\x20Apr\x202025\x2006:10:21\x20GMT\r\ncontent
    SF:-type:\x20text/html;charset=utf-8\r\ncontent-length:\x203541\r\nvary:\x
    SF:20Accept-Language\r\ncontent-language:\x20en\r\nconnection:\x20close\r\
    SF:n\r\n<!DOCTYPE\x20html\x20PUBLIC\x20\"-//W3C//DTD\x20HTML\x204\.01//EN\
    SF:"\x20\"http://www\.w3\.org/TR/html4/strict\.dtd\">\n<html><head>\n<meta
    SF:\x20type=\"copyright\"\x20content=\"Copyright\x20\(C\)\x201996-2020\x20
    SF:The\x20Squid\x20Software\x20Foundation\x20and\x20contributors\">\n<meta
    SF:\x20http-equiv=\"Content-Type\"\x20content=\"text/html;\x20charset=utf-
    SF:8\">\n<title>ERROR:\x20The\x20requested\x20URL\x20could\x20not\x20be\x2
    SF:0retrieved</title>\n<style\x20type=\"text/css\"><!--\x20\n\x20/\*\n\x20
    SF:\*\x20Copyright\x20\(C\)\x201996-2023\x20The\x20Squid\x20Software\x20Fo
    SF:undation\x20and\x20contributors\n\x20\*\n\x20\*\x20Squid\x20software\x2
    SF:0is\x20distributed\x20under\x20GPLv2\+\x20license\x20and\x20includes\n\
    SF:x20\*\x20contributions\x20from\x20numerous\x20individuals\x20and\x20org
    SF:anizations\.\n\x20\*\x20Please\x20see\x20the\x20COPYING\x20and\x20CONTR
    SF:IBUTORS\x20files\x20for\x20details\.\n\x20\*/\n\n/\*\n\x20Stylesheet\x2
    SF:0for\x20Squid\x20Error\x20pages\n\x20Adapted")%r(HTTPOptions,EA6,"HTTP/
    SF:1\.1\x20400\x20Bad\x20Request\r\nmime-version:\x201\.0\r\ndate:\x20Tue,
    SF:\x2022\x20Apr\x202025\x2006:10:22\x20GMT\r\ncontent-type:\x20text/html;
    SF:charset=utf-8\r\ncontent-length:\x203541\r\nvary:\x20Accept-Language\r\
    SF:ncontent-language:\x20en\r\nconnection:\x20close\r\n\r\n<!DOCTYPE\x20ht
    SF:ml\x20PUBLIC\x20\"-//W3C//DTD\x20HTML\x204\.01//EN\"\x20\"http://www\.w
    SF:3\.org/TR/html4/strict\.dtd\">\n<html><head>\n<meta\x20type=\"copyright
    SF:\"\x20content=\"Copyright\x20\(C\)\x201996-2020\x20The\x20Squid\x20Soft
    SF:ware\x20Foundation\x20and\x20contributors\">\n<meta\x20http-equiv=\"Con
    SF:tent-Type\"\x20content=\"text/html;\x20charset=utf-8\">\n<title>ERROR:\
    SF:x20The\x20requested\x20URL\x20could\x20not\x20be\x20retrieved</title>\n
    SF:<style\x20type=\"text/css\"><!--\x20\n\x20/\*\n\x20\*\x20Copyright\x20\
    SF:(C\)\x201996-2023\x20The\x20Squid\x20Software\x20Foundation\x20and\x20c
    SF:ontributors\n\x20\*\n\x20\*\x20Squid\x20software\x20is\x20distributed\x
    SF:20under\x20GPLv2\+\x20license\x20and\x20includes\n\x20\*\x20contributio
    SF:ns\x20from\x20numerous\x20individuals\x20and\x20organizations\.\n\x20\*
    SF:\x20Please\x20see\x20the\x20COPYING\x20and\x20CONTRIBUTORS\x20files\x20
    SF:for\x20details\.\n\x20\*/\n\n/\*\n\x20Stylesheet\x20for\x20Squid\x20Err
    SF:or\x20pages\n\x20Adapted");
    Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
    Device type: general purpose
    Running (JUST GUESSING): Linux 4.X|5.X|2.6.X|3.X (91%)
    OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:linux:linux_kernel:2.6.32 cpe:/o:linux:linux_kernel:3.10
    OS fingerprint not ideal because: Missing a closed TCP port so results incomplete
    Aggressive OS guesses: Linux 4.15 - 5.8 (91%), Linux 5.0 - 5.4 (91%), Linux 2.6.32 (90%), Linux 4.4 (90%), Linux 5.0 - 5.5 (89%), Linux 2.6.32 or 3.10 (89%), Linux 2.6.32 - 2.6.35 (87%), Linux 2.6.32 - 2.6.39 (87%)
    No exact OS matches for host (test conditions non-ideal).
    TCP/IP fingerprint:
    SCAN(V=7.94SVN%E=4%D=4/22%OT=80%CT=%CU=%PV=N%DS=13%DC=T%G=N%TM=6807330E%P=x86_64-pc-linux-gnu)
    SEQ(SP=106%GCD=1%ISR=10C%TI=Z%II=I%TS=A)
    OPS(O1=M5B4ST11NW7%O2=M5B4ST11NW7%O3=M5B4NNT11NW7%O4=M5B4ST11NW7%O5=M5B4ST11NW7%O6=M5B4ST11)
    WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=FE88)
    ECN(R=Y%DF=Y%TG=40%W=FAF0%O=M5B4NNSNW7%CC=Y%Q=)
    T1(R=Y%DF=Y%TG=40%S=O%A=S+%F=AS%RD=0%Q=)
    T2(R=N)
    T3(R=N)
    T4(R=N)
    U1(R=N)
    IE(R=Y%DFI=N%TG=40%CD=S)
    
    Uptime guess: 4.698 days (since Thu Apr 17 13:26:18 2025)
    Network Distance: 13 hops
    TCP Sequence Prediction: Difficulty=262 (Good luck!)
    IP ID Sequence Generation: All zeros
    
    TRACEROUTE (using port 8080/tcp)
    HOP RTT       ADDRESS
    1   1.18 ms   _gateway (10.199.22.3)
    2   0.30 ms   rtr-ge-dmarc.tblflp.net (10.199.1.1)
    3   ...
    4   3.75 ms   rcmt-agw1.inet.qwest.net (71.32.31.17)
    5   31.28 ms  4.68.144.73
    6   128.24 ms ae1.10.edge1.ist2.neo.colt.net (171.75.9.47)
    7   163.56 ms 213.249.104.190
    8   163.55 ms 188-123-128-99.dsl.utg.ge (188.123.128.99)
    9   157.05 ms 178-134-198-41.dsl.utg.ge (178.134.198.41)
    10  156.50 ms 178-134-198-42.dsl.utg.ge (178.134.198.42)
    11  ...
    12  163.07 ms 91.208.144.217
    13  169.51 ms 194.135.119.59
    
    Open proxy blocked Naomi Amethyst 06:13, 22 April 2025 (UTC)[reply]

    112.199.95.188

    – This proxy check request is closed and will soon be archived by a bot.

    Reason: Block evasion via proxy. (See above reports.) Tule-hog (talk) 01:54, 23 April 2025 (UTC)[reply]

     Likely IP is an open proxy
    Nmap scan report for 188.95.199.112.clbrz.static.inet.eastern-tele.com (112.199.95.188)
    Host is up, received user-set (0.22s latency).
    Scanned at 2025-04-24 19:52:21 UTC for 78s
    
    PORT      STATE    SERVICE          REASON         VERSION
    21/tcp    filtered ftp              no-response
    22/tcp    filtered ssh              no-response
    80/tcp    open     http             syn-ack ttl 54
    |_http-title: ERROR: The requested URL could not be retrieved
    | fingerprint-strings:
    |   GetRequest:
    |     HTTP/1.1 400 Bad Request
    |     mime-version: 1.0
    |     date: Thu, 24 Apr 2025 19:52:32 GMT
    |     content-type: text/html;charset=utf-8
    |     content-length: 3541
    |     vary: Accept-Language
    |     content-language: en
    |     connection: close
    |     <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
    |     <html><head>
    |     <meta type="copyright" content="Copyright (C) 1996-2020 The Squid Software Foundation and contributors">
    |     <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
    |     <title>ERROR: The requested URL could not be retrieved</title>
    |     <style type="text/css"><!--
    |     Copyright (C) 1996-2023 The Squid Software Foundation and contributors
    |     Squid software is distributed under GPLv2+ license and includes
    |     contributions from numerous individuals and organizations.
    |     Please see the COPYING and CONTRIBUTORS files for details.
    |     Stylesheet for Squid Error pages
    |     Adapted
    |   HTTPOptions:
    |     HTTP/1.1 400 Bad Request
    |     mime-version: 1.0
    |     date: Thu, 24 Apr 2025 19:52:33 GMT
    |     content-type: text/html;charset=utf-8
    |     content-length: 3541
    |     vary: Accept-Language
    |     content-language: en
    |     connection: close
    |     <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
    |     <html><head>
    |     <meta type="copyright" content="Copyright (C) 1996-2020 The Squid Software Foundation and contributors">
    |     <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
    |     <title>ERROR: The requested URL could not be retrieved</title>
    |     <style type="text/css"><!--
    |     Copyright (C) 1996-2023 The Squid Software Foundation and contributors
    |     Squid software is distributed under GPLv2+ license and includes
    |     contributions from numerous individuals and organizations.
    |     Please see the COPYING and CONTRIBUTORS files for details.
    |     Stylesheet for Squid Error pages
    |_    Adapted
    443/tcp   filtered https            no-response
    1080/tcp  filtered socks            no-response
    3182/tcp  filtered bmcpatrolrnvu    no-response
    5000/tcp  filtered upnp             no-response
    8000/tcp  filtered http-alt         no-response
    8080/tcp  open     http-proxy?      syn-ack ttl 54
    8443/tcp  filtered https-alt        no-response
    8888/tcp  filtered sun-answerbook   no-response
    9050/tcp  filtered tor-socks        no-response
    9150/tcp  filtered unknown          no-response
    10000/tcp filtered snet-sensor-mgmt no-response
    20000/tcp filtered dnp              no-response
    1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
    SF-Port80-TCP:V=7.94SVN%I=7%D=4/24%Time=680A9680%P=x86_64-pc-linux-gnu%r(G
    SF:etRequest,EA6,"HTTP/1\.1\x20400\x20Bad\x20Request\r\nmime-version:\x201
    SF:\.0\r\ndate:\x20Thu,\x2024\x20Apr\x202025\x2019:52:32\x20GMT\r\ncontent
    SF:-type:\x20text/html;charset=utf-8\r\ncontent-length:\x203541\r\nvary:\x
    SF:20Accept-Language\r\ncontent-language:\x20en\r\nconnection:\x20close\r\
    SF:n\r\n<!DOCTYPE\x20html\x20PUBLIC\x20\"-//W3C//DTD\x20HTML\x204\.01//EN\
    SF:"\x20\"http://www\.w3\.org/TR/html4/strict\.dtd\">\n<html><head>\n<meta
    SF:\x20type=\"copyright\"\x20content=\"Copyright\x20\(C\)\x201996-2020\x20
    SF:The\x20Squid\x20Software\x20Foundation\x20and\x20contributors\">\n<meta
    SF:\x20http-equiv=\"Content-Type\"\x20content=\"text/html;\x20charset=utf-
    SF:8\">\n<title>ERROR:\x20The\x20requested\x20URL\x20could\x20not\x20be\x2
    SF:0retrieved</title>\n<style\x20type=\"text/css\"><!--\x20\n\x20/\*\n\x20
    SF:\*\x20Copyright\x20\(C\)\x201996-2023\x20The\x20Squid\x20Software\x20Fo
    SF:undation\x20and\x20contributors\n\x20\*\n\x20\*\x20Squid\x20software\x2
    SF:0is\x20distributed\x20under\x20GPLv2\+\x20license\x20and\x20includes\n\
    SF:x20\*\x20contributions\x20from\x20numerous\x20individuals\x20and\x20org
    SF:anizations\.\n\x20\*\x20Please\x20see\x20the\x20COPYING\x20and\x20CONTR
    SF:IBUTORS\x20files\x20for\x20details\.\n\x20\*/\n\n/\*\n\x20Stylesheet\x2
    SF:0for\x20Squid\x20Error\x20pages\n\x20Adapted")%r(HTTPOptions,EA6,"HTTP/
    SF:1\.1\x20400\x20Bad\x20Request\r\nmime-version:\x201\.0\r\ndate:\x20Thu,
    SF:\x2024\x20Apr\x202025\x2019:52:33\x20GMT\r\ncontent-type:\x20text/html;
    SF:charset=utf-8\r\ncontent-length:\x203541\r\nvary:\x20Accept-Language\r\
    SF:ncontent-language:\x20en\r\nconnection:\x20close\r\n\r\n<!DOCTYPE\x20ht
    SF:ml\x20PUBLIC\x20\"-//W3C//DTD\x20HTML\x204\.01//EN\"\x20\"http://www\.w
    SF:3\.org/TR/html4/strict\.dtd\">\n<html><head>\n<meta\x20type=\"copyright
    SF:\"\x20content=\"Copyright\x20\(C\)\x201996-2020\x20The\x20Squid\x20Soft
    SF:ware\x20Foundation\x20and\x20contributors\">\n<meta\x20http-equiv=\"Con
    SF:tent-Type\"\x20content=\"text/html;\x20charset=utf-8\">\n<title>ERROR:\
    SF:x20The\x20requested\x20URL\x20could\x20not\x20be\x20retrieved</title>\n
    SF:<style\x20type=\"text/css\"><!--\x20\n\x20/\*\n\x20\*\x20Copyright\x20\
    SF:(C\)\x201996-2023\x20The\x20Squid\x20Software\x20Foundation\x20and\x20c
    SF:ontributors\n\x20\*\n\x20\*\x20Squid\x20software\x20is\x20distributed\x
    SF:20under\x20GPLv2\+\x20license\x20and\x20includes\n\x20\*\x20contributio
    SF:ns\x20from\x20numerous\x20individuals\x20and\x20organizations\.\n\x20\*
    SF:\x20Please\x20see\x20the\x20COPYING\x20and\x20CONTRIBUTORS\x20files\x20
    SF:for\x20details\.\n\x20\*/\n\n/\*\n\x20Stylesheet\x20for\x20Squid\x20Err
    SF:or\x20pages\n\x20Adapted");
    Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
    Device type: general purpose
    Running (JUST GUESSING): Linux 4.X|5.X|2.6.X|3.X (91%)
    OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:linux:linux_kernel:2.6.32 cpe:/o:linux:linux_kernel:3.10
    OS fingerprint not ideal because: Missing a closed TCP port so results incomplete
    Aggressive OS guesses: Linux 4.15 - 5.8 (91%), Linux 5.0 - 5.4 (91%), Linux 2.6.32 (90%), Linux 4.4 (90%), Linux 5.0 - 5.5 (89%), Linux 2.6.32 or 3.10 (89%), Linux 2.6.32 - 2.6.35 (87%), Linux 2.6.32 - 2.6.39 (87%)
    No exact OS matches for host (test conditions non-ideal).
    TCP/IP fingerprint:
    SCAN(V=7.94SVN%E=4%D=4/24%OT=80%CT=%CU=%PV=N%DS=12%DC=T%G=N%TM=680A96C3%P=x86_64-pc-linux-gnu)
    SEQ(SP=107%GCD=1%ISR=10D%TI=Z%II=I%TS=A)
    OPS(O1=M5B4ST11NW7%O2=M5B4ST11NW7%O3=M5B4NNT11NW7%O4=M5B4ST11NW7%O5=M5B4ST11NW7%O6=M5B4ST11)
    WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=FE88)
    ECN(R=Y%DF=Y%TG=40%W=FAF0%O=M5B4NNSNW7%CC=Y%Q=)
    T1(R=Y%DF=Y%TG=40%S=O%A=S+%F=AS%RD=0%Q=)
    T2(R=N)
    T3(R=N)
    T4(R=N)
    U1(R=N)
    IE(R=Y%DFI=N%TG=40%CD=S)
    
    Uptime guess: 4.961 days (since Sat Apr 19 20:49:29 2025)
    Network Distance: 12 hops
    TCP Sequence Prediction: Difficulty=263 (Good luck!)
    IP ID Sequence Generation: All zeros
    
    TRACEROUTE (using port 8080/tcp)
    HOP RTT       ADDRESS
    1   0.87 ms   _gateway (10.199.22.3)
    2   0.27 ms   rtr-ge-dmarc.tblflp.net (10.199.1.1)
    3   ...
    4   3.47 ms   71-32-31-17.rcmt.qwest.net (71.32.31.17)
    5   26.89 ms  4.68.144.73
    6   ...
    7   12.69 ms  ae3.cr1-was1.ip4.gtt.net (199.229.230.97)
    8   205.26 ms et-4-1-0.cr1-hkg1.ip4.gtt.net (89.149.131.66)
    9   228.40 ms ip4.gtt.net (103.232.18.30)
    10  225.42 ms 162.1.89.120.core-net.static.eastern-tele.com (120.89.1.162)
    11  217.01 ms 124.6.180.10
    12  217.77 ms 188.95.199.112.clbrz.static.inet.eastern-tele.com (112.199.95.188)
    
    Open proxy blocked Naomi Amethyst 19:57, 24 April 2025 (UTC)[reply]

    119.231.70.144

    – This proxy check request is closed and will soon be archived by a bot.

    Reason: Vandalizing USSR anti-religious campaign (1958–1964). jlwoodwa (talk) 20:03, 28 April 2025 (UTC)[reply]

    Open proxy blocked as part of VPN Gate. Naomi Amethyst 07:25, 30 April 2025 (UTC)[reply]

    59.187.201.43

    – This proxy check request is closed and will soon be archived by a bot.

    Reason: Vandalizing USSR anti-religious campaign (1958–1964). jlwoodwa (talk) 20:22, 28 April 2025 (UTC)[reply]

    Open proxy blocked as part of VPN Gate. Naomi Amethyst 07:25, 30 April 2025 (UTC)[reply]

    42.114.80.68

    – This proxy check request is closed and will soon be archived by a bot.

    Reason: Vandalizing KGB. jlwoodwa (talk) 23:03, 28 April 2025 (UTC)[reply]

    Open proxy blocked as part of VPN Gate. Naomi Amethyst 07:26, 30 April 2025 (UTC)[reply]

    38.158.220.26

    – This proxy check request is closed and will soon be archived by a bot.

    Reason: Block evasion, see SPI. Tule-hog (talk) 17:06, 7 May 2025 (UTC)[reply]

    Open proxy blocked Naomi Amethyst 22:56, 7 May 2025 (UTC)[reply]

    195.82.104.0/23

    – This proxy check request is closed and will soon be archived by a bot.

    195.82.104.0/23 · contribs · block · log · stalk · Robtex · whois · Google

    This is a rangeblock for a datacentre, AS43160, but it doesn't look like that's accurate anymore. Got here via an unblock request for 195.82.104.57, which is currently showing as AS200845. Would appreciate if someone could double-check this and unblock as appropriate. asilvering (talk) 21:41, 7 May 2025 (UTC)[reply]

    You are correct that the ASN has changed and it looks like the range is now owned by a different company, but there's definitely some hosting still going on there, even on the individual IP address. It's the webhost for iberofurs, for example:
    Nmap scan report for 57.104.82.195-avatel.es (195.82.104.57)
    Host is up, received user-set (0.12s latency).
    Scanned at 2025-05-07 23:03:17 UTC for 174s
    Not shown: 65534 filtered tcp ports (no-response)
    PORT    STATE SERVICE  REASON         VERSION
    80/tcp  open  http     syn-ack ttl 49 Apache httpd 2.4.62
    | http-robots.txt: 1 disallowed entry
    |_/wp-admin/
    |_http-title: iberofurs
    |_http-generator: WordPress 6.8.1
    |_http-server-header: Apache/2.4.62 (Debian)
    | http-methods:
    |_  Supported Methods: GET HEAD POST OPTIONS
    443/tcp open  ssl/http syn-ack ttl 49 Apache httpd 2.4.62 ((Debian))
    |_http-server-header: Apache/2.4.62 (Debian)
    |_ssl-date: TLS randomness does not represent time
    |_http-generator: WordPress 6.8.1
    | ssl-cert: Subject: commonName=iberofurs.org
    | Subject Alternative Name: DNS:iberofurs.org, DNS:www.iberofurs.org
    | Issuer: commonName=E6/organizationName=Let's Encrypt/countryName=US
    | Public Key type: ec
    | Public Key bits: 256
    | Signature Algorithm: ecdsa-with-SHA384
    | Not valid before: 2025-04-03T18:14:39
    | Not valid after:  2025-07-02T18:14:38
    | MD5:   5b1e:fe2b:92bf:6a26:101f:0675:ca7b:7bc5
    | SHA-1: 1d3a:f34d:6436:797c:1fd6:eed9:0078:6430:7fc3:4d12
    | -----BEGIN CERTIFICATE-----
    | MIIDvjCCA0OgAwIBAgISBZV+b1B69qEFgiNr7zvjsOAbMAoGCCqGSM49BAMDMDIx
    | CzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQswCQYDVQQDEwJF
    | NjAeFw0yNTA0MDMxODE0MzlaFw0yNTA3MDIxODE0MzhaMBgxFjAUBgNVBAMTDWli
    | ZXJvZnVycy5vcmcwWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAARI7C+HnTaP/srV
    | tbdnAjPeJ95IsSbKlZayq7pSFy1o5tua/+Je8Kmson/pMVvNafl/yVaC4mo8+JW3
    | AtyfAtMQo4ICUTCCAk0wDgYDVR0PAQH/BAQDAgeAMB0GA1UdJQQWMBQGCCsGAQUF
    | BwMBBggrBgEFBQcDAjAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBSXgd83GxuSTYlA
    | SFmuASnHpaLNCTAfBgNVHSMEGDAWgBSTJ0aYA6lRaI6Y1sRCSNsjv1iU0jBVBggr
    | BgEFBQcBAQRJMEcwIQYIKwYBBQUHMAGGFWh0dHA6Ly9lNi5vLmxlbmNyLm9yZzAi
    | BggrBgEFBQcwAoYWaHR0cDovL2U2LmkubGVuY3Iub3JnLzArBgNVHREEJDAigg1p
    | YmVyb2Z1cnMub3JnghF3d3cuaWJlcm9mdXJzLm9yZzATBgNVHSAEDDAKMAgGBmeB
    | DAECATAtBgNVHR8EJjAkMCKgIKAehhxodHRwOi8vZTYuYy5sZW5jci5vcmcvMjgu
    | Y3JsMIIBBAYKKwYBBAHWeQIEAgSB9QSB8gDwAHYAEvFONL1TckyEBhnDjz96E/jn
    | tWKHiJxtMAWE6+WGJjoAAAGV/RJKcAAABAMARzBFAiBC+RoBgVWxiS2fHGyHMek1
    | U4+VW8aJGw1KGZ1xCEt7NgIhAMomMLKrsQJ0i9d+EYebooaS+J28MbVuULYaAgw6
    | 2Y2uAHYA7TxL1ugGwqSiAFfbyyTiOAHfUS/txIbFcA8g3bc+P+AAAAGV/RJSQwAA
    | BAMARzBFAiAoJqmO9ShA9Oa8ZTGgGOApnwhz4tjzhycBEqFgNHY7MwIhAIh7aKEl
    | /aW5nIlgDMD0FkhIegj2C4xcmKi8BArRkpaJMAoGCCqGSM49BAMDA2kAMGYCMQDU
    | VL5MFVIveATU1xB31mYGVs5GYSlldHCQGrDpZ6g+U3GX6rxpnQrJXJ9CpWeQy2cC
    | MQDTwxX6tWoeFtRNsFmMguEwLJYfTgBraNU0JASzGkn32LLDfhkQ6aw+oe09hr60
    | q8I=
    |_-----END CERTIFICATE-----
    |_http-title: iberofurs
    | http-methods:
    |_  Supported Methods: GET HEAD POST OPTIONS
    | http-robots.txt: 1 disallowed entry
    |_/wp-admin/
    Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
    OS fingerprint not ideal because: Missing a closed TCP port so results incomplete
    No OS matches for host
    TCP/IP fingerprint:
    SCAN(V=7.94SVN%E=4%D=5/7%OT=80%CT=%CU=%PV=N%DS=14%DC=T%G=N%TM=681BE763%P=x86_64-pc-linux-gnu)
    SEQ(SP=107%GCD=1%ISR=10B%TI=Z%II=I%TS=A)
    OPS(O1=M584ST11NW7%O2=M584ST11NW7%O3=M584NNT11NW7%O4=M584ST11NW7%O5=M584ST11NW7%O6=M584ST11)
    WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=FE88)
    ECN(R=Y%DF=Y%TG=40%W=FAF0%O=M584NNSNW7%CC=Y%Q=)
    T1(R=Y%DF=Y%TG=40%S=O%A=S+%F=AS%RD=0%Q=)
    T2(R=N)
    T3(R=N)
    T4(R=N)
    U1(R=N)
    IE(R=Y%DFI=N%TG=40%CD=S)
    
    Uptime guess: 2.371 days (since Mon May  5 14:11:29 2025)
    Network Distance: 14 hops
    TCP Sequence Prediction: Difficulty=263 (Good luck!)
    IP ID Sequence Generation: All zeros
    Service Info: Host: iberofurs.org
    
    TRACEROUTE (using port 443/tcp)
    HOP RTT       ADDRESS
    1   0.96 ms   _gateway (10.199.22.3)
    2   0.46 ms   rtr-ge-dmarc.tblflp.net (10.199.1.1)
    3   ...
    4   3.94 ms   rcmt-agw1.inet.qwest.net (71.32.31.17)
    5   19.69 ms  4.68.144.73
    6   11.95 ms  1299-3356-wdc.sp.lumen.tech (4.68.111.150)
    7   11.98 ms  ash-bb2-link.ip.twelve99.net (62.115.123.124)
    8   ...
    9   110.19 ms mad-b3-link.ip.twelve99.net (62.115.123.219)
    10  108.39 ms avateltelecom-ic-374237.ip.twelve99-cust.net (62.115.172.69)
    11  ... 13
    14  124.00 ms 57.104.82.195-avatel.es (195.82.104.57)
    
    Also 195.82.104.28 has a Watchguard device, 195.82.104.2 has a webcam, and the list goes on and on. The range is too big to do an in-depth test of each, but it is very  Likely IP is an open proxy Naomi Amethyst 23:14, 7 May 2025 (UTC)[reply]
    Alas for this blocked editor. Thanks for the double-check. -- asilvering (talk) 23:24, 7 May 2025 (UTC)[reply]
    Wait, I think that website is them, actually. UTRS appeal #102938 is the relevant appeal. -- asilvering (talk) 23:33, 7 May 2025 (UTC)[reply]

    Automated lists and tools

    • User:AntiCompositeBot/ASNBlock maintained by User:AntiCompositeBot is a list of hosting provider ranges that need assessment for blocks that is updated daily. Admins are encouraged to review the list and assess for blocks as needed. All administrators are individually responsible for any blocks they make based on that list.
    • ISP Rangefinder is a tool that allows administrators to easily identify and hard block all ranges for an entire ISP. It should be used with extreme caution, but is useful for blocking known open proxy providers. All administrators are individually responsible for any blocks they make based on the results from this tool.
    • IPCheck is a tool that can help provide clues about potential open proxies.
    • Bullseye provides information about IPS, including clues about potential open proxies.
    • whois-referral is a generic WHOIS tool.
    • Range block finder finds present and past range blocks.

    See also

    Subpages
    Related pages
    Sister projects (defunct)
    Uses material from the Wikipedia article Wikipedia:Open proxies noticeboard, released under the CC BY-SA 4.0 license.