Show HN: IPalyzer – Analyze any IP for location, RDNS, blacklisting
ipalyzer.com
ipalyzer.com
Spamhaus says the following in its FAQ about the PBL (https://www.spamhaus.org/faq/section/Spamhaus%20PBL#183):
"The first thing to know is: THE PBL IS NOT A BLACKLIST. You are not listed for spamming or for anything you have done. The PBL is simply a list of all of the world's dynamic IP space, i.e: IP ranges normally assigned to ISP broadband customers (DSL, DHCP, PPP, cable, dialup). It is perfectly normal for dynamic IP addresses to be listed on the PBL. In fact all dynamic IP addresses in the world should be on the PBL. Even static IPs which do not send mail should be listed in the PBL."
So, in this tool, presumably any dynamic IP will turn up as "Listed in spamhaus PBL", which might cause some undue alarm to the uninformed. Maybe you should just show a yellow warning saying "you're a dynamic IP address" or something of that sort.
Congrats on the tool, it is really neat!
$ curl ipinfo.io/8.8.8.8
{
"ip": "8.8.8.8",
"hostname": "google-public-dns-a.google.com",
"city": "Mountain View",
"region": "California",
"country": "US",
"loc": "37.3845,-122.0881",
"org": "AS15169 Google Inc.",
"postal": "94040"
}
$ curl ipinfo.io/8.8.8.8/org
AS15169 Google Inc.
It also supports lookup of IPv6 addresses (but not IPv6 connections, due to AWS). See http://ipinfo.io/about for more detailsedit: for checking ports: shodan.io for (r)dns: robtex.com
There are some issues with the port detection on my IP address though: HTTP was 'disabled' (whatever that means, but it's open and apache is listening) and SMTP was incorrectly labeled 'closed'. Https detection was correct, and ssh was 'closed', which could be correct if it means 'RST returned' rather than 'firewalled'.
Also I'd prefer seeing an OpenStreetMap tile rather than having Google log my visit, but that is probably just me. On the positive side, Piwik instead of GA :)
Another small point: I'm not sure which address you're looking for, but the whois info of my IP definitely contains an abuse address (80.100.131.150).
Abuse mails get parsed from the RIR WHOIS data, this involves lots of regexes, which can be wrong sometimes. In your specific case it is the fact that it can't yet parse the remarks statement.
edit: Just noticed it's also loading fonts from Google
Suggestion: Accept host names as well, despite the name of the service.
Obviously a hostname could resolve to multiple IPs or no IPs, but that's a solvable problem.
No so much "any IP" then, is it?
https://myip.ms/info/whois/212.51.131.143 https://www.domaintally.com/hosted-ip/212.51.131.143/
why don't you use some service to get city by long/lat? i think google should have something for this