If their request IP doesn't match up with this IP, there's a very high chance that the order will is fraudulent.
If their request IP doesn't match up with this IP, there's a very high chance that the order will is fraudulent.
;)
Another useful heuristic is to check if the client is coming in from a public Tor exit. YMMV depending on the nature of goods being sold, but in our case not a single legit purchase came in this way and nearly all fraudulent purchases were through Tor.
HTTP proxy is not a SOCKS4 is not a SOCKS5. :)
What they'll do is buy from a proxy shop " " - usually someone(s) with a botnet and a lot of clients on that botnet - so the IPs are residentials. vip72.com is a popular one. They do provide a client which will allow you to tunnel your entire system through the proxy, but it's not required for use (and some people are wary of it)
> i think only amateurs would be so foolish
When I think of people using stolen credit cards to buy goods, I'm not envisaging a `leet hacking squad... That there are highly sophisticated cyber criminals in no way implies that all - or even most - are.