HNHacker News
TopNewBestAskShowJobs

tuxxin

6 karma · joined April 17, 2026

Founder and Managing Member @ Tuxxin LLC

Serial Entrepreneur & Tech Nerd

Building multiple SaaS, Cyber-Security, & Open-Source platforms

Passionate about creating secure, innovative, and community-driven software solutions.

submissionscomments
tuxxin··on [dead]
Traffic Direction Systems (TDS) have become a massive headache for analysts. By fingerprinting IPs, attackers can dynamically route traffic—hiding malicious payloads from security tools while successfully targeting residential, mobile, or specific ASNs.

The problem? Almost every URL scanner out there uses datacenter-based egress IPs. Attackers know this, so they block or cloak against datacenter ranges.

I ran into this wall while investigating malware distributed via a lapsed corporate domain. The standard scanners were returning clean results or blocked pages, but my home connection was still being served malware. Doing the analysis manually was a massive bottleneck, so I built a solution: whack.sh.

What it does: Whack allows you to scan any URL simultaneously through multiple egress options: Datacenter, Residential, Mobile, VPN, and even BYO IP. It then diffs the captures (HAR files) to expose the cloaking, TDS routing, phishing, and malware that traditional datacenter-only scanners miss. The Origin & Investigation: I’ve been working on this for over a month and have already run over 150,000 scans of known threat URLs. The early MVP was basic but proved the concept: diffing HAR files of the exact same URL across different categorized ASNs immediately exposed the evasion tactics.

I actually reported my initial findings on this specific threat to the FBI IC3 on Monday, June 15th. Three days later, IC3 pushed out a PSA specifically regarding TDS. (I’ll be publishing a few in-depth articles on my company's site detailing these findings in the coming weeks).

Under the Hood (TDS-over-TDS): One of the most interesting things the tool exposed during this process is that TDS isn't just happening at the redirect layer. I found several instances of TDS-over-TDS (redirect layer + payload delivery layer). Malicious actors are using real-time API calls or compressed local IP intelligence to serve entirely different payloads based on the exact environment (e.g., Windows vs. Mobile/Android/Chrome vs. Mobile/iOS/Safari).

Community Integration: I want this data to be useful to the broader community, so any threats found by whack.sh are automatically published to Abuse.ch:https://bazaar.abuse.ch/user/42023/

I’m putting the final polish on the site and planning to officially launch on or before August 4th. In the meantime, I would love to hear your thoughts on the concept! What features would you want to see, or what specific evasion tactics would you want to test against it when it goes live?

tuxxin··on Show HN: A free curl API for IP data (we scan the IPv4 space in <24h)
Thanks for the feedback!

I've recently started aggregating my own location data to run alongside MaxMind. If you don't mind sharing a few of the IPs that were off, I'd love to take a look and see if there's a dataset bug.

Good call on the range pages, too—I’ll look into handling unallocated blocks more like bgp.tools. Appreciate you bringing it to my attention!

tuxxin··on Show HN: A free curl API for IP data (we scan the IPv4 space in <24h)
I've been collecting IPv6 data for a few weeks using my older v1 scanner. However, I just launched a v4 scanner for IPv4 (which is 10-12x faster with the same accuracy) and I'll be porting that over soon. You can already see some IPv6 details scattered across the site, but the full dataset will be live in the coming weeks.
tuxxin··on The complete IPv4 address space, mapped
There's actually 13 Easter eggs :)
tuxxin··on The complete IPv4 address space, mapped
Yes, currently 12 POP's. See worldip.io/infrastructure
tuxxin··on The complete IPv4 address space, mapped
I'm actually the person who created the website. Of course I used AI. Yes the website is displaying inaccurate information but this was due to my attention moving to collecting and retaining accurate data (a lot harder than most of you'd think). Given the scale of the site and infrastructure behind it there's been a lot of trial and error. https://worldip.io/about if you'd care to read more.

That data collection is about 90% solid right now, once I have it 100% I'll begin updating the frontend to read from the proper tables (currently displaying a lot of stale data). Keep checking back on the site and you'll see those changes.

This is why the website is completely free, no account or pay gates. I do plan to offer as a SaaS in time (whoever commented about batch files, I'll be offering those as well), but again this won't be done until I'm certain the captured data is 100% correct.

Thank you to those of you who gave useful feedback.

tuxxin··on The complete IPv4 address space, mapped
I'm actually the person who created the website and yes, geo location means nothing with the bulk of the IP space.