Repository files navigation

M2 AbuseIPDB API Integration

Url:https://github.com/df2k2/magento2-abuse-api

Author: Chris Snedaker

Date: 2020-06-17


CURRENTLY BEING DEVELOPED

Objective

Create a Magento2 integration to AbuseIPDB API

Website:https://www.abuseipdb.com/

Documentation URL:https://docs.abuseipdb.com/

Unfortunately, too many bots and bad actors are out to take advantage of security flaws.

Purpose

The initial integration will use two different endpoints for:

  • Check IPs
  • Report IPs

Check IPs (https://docs.abuseipdb.com/#check-endpoint)

Use the abuse ip database API to check IPs that seem to be up to no good and take an action based on response to checked IP

Example: https://www.abuseipdb.com/check/115.84.92.92

Below is a chart of problematic IPs attempting to hack/DoS a production magento website in a single day.

ipAddress countryCode isp domain abuseConfidenceScore totalReports
--------- ----------- --- ------ -------------------- ------------
115.84.92.92 LA Telecommunication Service newworldtelecom.net 100 93
34.87.251.211 US Google LLC google.com 100 19
66.70.157.189 CA Kazooisyee ip-66-70-157.net 51 9
144.217.171.225 CA Kazooisyee ip-144-217-171.net 48 9
14.178.144.104 VN Vietnam Posts and Telecommunications Group vnpt.com.vn 46 7
167.114.90.33 CA Kazooisyee ip-167-114-90.net 44 11
188.191.22.226 UA CrimeaCom South LLC crimea-com.net 42 17
198.27.124.169 CA Kazooisyee ip-198-27-124.net 35 11
144.217.99.65 CA Kazooisyee ip-144-217-99.net 34 8
144.217.171.229 CA Kazooisyee ip-144-217-171.net 34 7
216.244.66.197 US Wowrack.com wowrack.com 32 120
66.249.68.25 US Google LLC google.com 22 12
47.244.217.16 HK Alibaba.com LLC alibaba.com 21 3

Report IPs (https://docs.abuseipdb.com/#report-endpoint)

NOT YET IMPLEMENTED

Report problematic IPs to the abuse IP database

Installation

Install as composer package -- instructions to come.

Step 1. Enable Module

php bin/magento module:enable Cs_AbuseApi

Step 2. Magento setup:upgrade

php bin/magento setup:upgrade

Step 3. Clear cache and compile DI

php bin magento setup:di:compile && php bin/magento cache:flush

Step 4. Update Admin Configuration settings

Update configuration settings in admin: Stores > Configuration > Abuse Api Db

  • Enable module

  • Register For API Key and copy API Key into configuration field

https://www.abuseipdb.com/register

API Key

https://www.abuseipdb.com/register

Register for API Key.


Usage Example

<?phpuseCs\AbuseApi\Model\Service****Client;
//....class Testclass {
private$serviceClient;
//...publicfunction__construct(
ServiceClient$serviceClient
) {
$this->serviceClient = $serviceClient;
}
publicfunctiontestIpCheck($ip) {
return$this->serviceClient->checkIp($ip);
} publicfunctiontestIpsCheck($ips)
{
$collection = $this->serviceClient->checkIps([
'34.87.251.211',
'66.70.157.189',
'144.217.171.225',
'14.178.144.104',
'167.114.90.33',
'188.191.22.226',
'198.27.124.169'
],90);
return$collection;
}
}

Example Output

object(Cs\AbuseApi\Model\Client\CheckResponse)[416]
protected '_data' => array (size=13)
'ipAddress' => string '115.84.92.92' (length=12)
'isPublic' => boolean true
'ipVersion' => int 4
'isWhitelisted' => boolean false
'abuseConfidenceScore' => int 100
'countryCode' => string 'LA' (length=2)
'usageType' => null
'isp' => string 'Telecommunication Service' (length=25)
'domain' => string 'newworldtelecom.net' (length=19)
'hostnames' => array (size=0)
empty
'totalReports' => int 41
'numDistinctUsers' => int 12
'lastReportedAt' => string '2020-09-14T17:23:53+00:00' (length=25)

API Key

https://www.abuseipdb.com/register

account/api

Developer Notes:

Configuration Fields

Base URI => 'base_uri' API Key => 'api_key' Max Days => 'max_days'

Client and HEADERS

<?php$client = newGuzzleHttp\Client([
'base_uri' => 'https://api.abuseipdb.com/api/v2/'
]);
 'headers' => [
'Accept' => 'application/json',
'Key' => $YOUR_API_KEY
],

CHECK Endpoint

Check Parameters

fieldrequireddefaultminmax
ipAddressyes
maxAgeInDaysno301365
verboseno

$response = $client->request('GET', 'check', [ 'query' => [ 'ipAddress' => '118.25.6.39', 'maxAgeInDays' => '90', ],

Request Example

<?php$client = newGuzzleHttp\Client([
'base_uri' => 'https://api.abuseipdb.com/api/v2/'
]);
$response = $client->request('GET', 'check', [
'query' => [
'ipAddress' => '118.25.6.39',
'maxAgeInDays' => '90',
],
'headers' => [
'Accept' => 'application/json',
'Key' => $YOUR_API_KEY
],
]);
$output = $response->getBody();
// Store response as a PHP object.$ipDetails = json_decode($output, true);
?>

Response Example

{
"data": {
"ipAddress": "118.25.6.39",
"isPublic": true,
"ipVersion": 4,
"isWhitelisted": false,
"abuseConfidenceScore": 100,
"countryCode": "CN",
"countryName": "China",
"usageType": "Data Center/Web Hosting/Transit",
"isp": "Tencent Cloud Computing (Beijing) Co. Ltd",
"domain": "tencent.com",
"hostnames": [],
"totalReports": 1,
"numDistinctUsers": 1,
"lastReportedAt": "2018-12-20T20:55:14+00:00",
"reports": [
{
"reportedAt": "2018-12-20T20:55:14+00:00",
"comment": "Dec 20 20:55:14 srv206 sshd[13937]: Invalid user oracle from 118.25.6.39",
"categories": [
18,
22
],
"reporterId": 1,
"reporterCountryCode": "US",
"reporterCountryName": "United States"
}
]
}
}

Categories

IDTitleDescription
1DNS CompromiseAltering DNS records resulting in improper redirection.
2DNS PoisoningFalsifying domain server cache (cache poisoning).
3Fraud OrdersFraudulent orders.
4DDoS AttackParticipating in distributed denial-of-service (usually part of botnet).
5FTP Brute-Force
6Ping of DeathOversized IP packet.
7PhishingPhishing websites and/or email.
8Fraud VoIP
9Open ProxyOpen proxy, open relay, or Tor exit node.
10Web SpamComment/forum spam, HTTP referer spam, or other CMS spam.
11Email SpamSpam email content, infected attachments, and phishing emails. Note: Limit comments to only relevent information (instead of log dumps) and be sure to remove PII if you want to remain anonymous.
12Blog SpamCMS blog comment spam.
13VPN IPConjunctive category.
14Port ScanScanning for open ports and vulnerable services.
15Hacking
16SQL InjectionAttempts at SQL injection.
17SpoofingEmail sender spoofing.
18Brute-ForceCredential brute-force attacks on webpage logins and services like SSH, FTP, SIP, SMTP, RDP, etc. This category is seperate from DDoS attacks.
19Bad Web BotWebpage scraping (for email addresses, content, etc) and crawlers that do not honor robots.txt. Excessive requests and user agent spoofing can also be reported here.
20Exploited HostHost is likely infected with malware and being used for other attacks or to host malicious content. The host owner may not be aware of the compromise. This category is often used in combination with other attack categories.
21Web App AttackAttempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdmin and various other software plugins/solutions.
22SSHSecure Shell (SSH) abuse. Use this category in combination with more specific categories.
23IoT TargetedAbuse was targeted at an "Internet of Things" type device. Include information about what type of device was targeted in the comments.

"1 " => "" Altering DNS records resulting in improper redirection. ", "2 " => "" Falsifying domain server cache (cache poisoning). ", "3 " => "" Fraudulent orders. ", "4 " => "" Participating in distributed denial-of-service (usually part of botnet). ", "5 " => "" ", "6 " => "" Oversized IP packet. ", "7 " => "" Phishing websites and/or email. ", "8 " => "" ", "9 " => "" Open proxy, open relay, or Tor exit node. ", "10" => "Comment/forum spam, HTTP referer spam, or other CMS spam. ", "11" => "Spam email content, infected attachments, and phishing emails. Note: Limit comments to only relevant information (instead of log dumps) and be sure to remove PII if you want to remain anonymous. ", "12" => "CMS blog comment spam. ", "13" => "Conjunctive category. ", "14" => "Scanning for open ports and vulnerable services. ", "15" => "" ", "16" => "Attempts at SQL injection. ", "17" => "Email sender spoofing. ", "18" => "Credential brute-force attacks on webpage logins and services like SSH, FTP, SIP, SMTP, RDP, etc. This category is seperate from DDoS attacks. ", "19" => "Webpage scraping (for email addresses, content, etc) and crawlers that do not honor robots.txt. Excessive requests and user agent spoofing can also be reported here. ", "20" => "Host is likely infected with malware and being used for other attacks or to host malicious content. The host owner may not be aware of the compromise. This category is often used in combination with other attack categories. ", "21" => "Attempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdmin and various other software plugins/solutions. ", "22" => "Secure Shell (SSH) abuse. Use this category in combination with more specific categories. ", "23" => "Abuse was targeted at an "Internet of Things" type device. Include information about what type of device was targeted in the comments. ",

About

Magento2 Abuse IP DB Api Integration

Topics

Resources

Stars

5 stars

Watchers

1 watching

Forks

Releases

Sponsor this project

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

M2 AbuseIPDB API Integration

Url:https://github.com/df2k2/magento2-abuse-api

Author: Chris Snedaker

Date: 2020-06-17


CURRENTLY BEING DEVELOPED

Objective

Create a Magento2 integration to AbuseIPDB API

Website:https://www.abuseipdb.com/

Documentation URL:https://docs.abuseipdb.com/

Unfortunately, too many bots and bad actors are out to take advantage of security flaws.

Purpose

The initial integration will use two different endpoints for:

  • Check IPs
  • Report IPs

Check IPs (https://docs.abuseipdb.com/#check-endpoint)

Use the abuse ip database API to check IPs that seem to be up to no good and take an action based on response to checked IP

Example: https://www.abuseipdb.com/check/115.84.92.92

Below is a chart of problematic IPs attempting to hack/DoS a production magento website in a single day.

ipAddress countryCode isp domain abuseConfidenceScore totalReports
--------- ----------- --- ------ -------------------- ------------
115.84.92.92 LA Telecommunication Service newworldtelecom.net 100 93
34.87.251.211 US Google LLC google.com 100 19
66.70.157.189 CA Kazooisyee ip-66-70-157.net 51 9
144.217.171.225 CA Kazooisyee ip-144-217-171.net 48 9
14.178.144.104 VN Vietnam Posts and Telecommunications Group vnpt.com.vn 46 7
167.114.90.33 CA Kazooisyee ip-167-114-90.net 44 11
188.191.22.226 UA CrimeaCom South LLC crimea-com.net 42 17
198.27.124.169 CA Kazooisyee ip-198-27-124.net 35 11
144.217.99.65 CA Kazooisyee ip-144-217-99.net 34 8
144.217.171.229 CA Kazooisyee ip-144-217-171.net 34 7
216.244.66.197 US Wowrack.com wowrack.com 32 120
66.249.68.25 US Google LLC google.com 22 12
47.244.217.16 HK Alibaba.com LLC alibaba.com 21 3

Report IPs (https://docs.abuseipdb.com/#report-endpoint)

NOT YET IMPLEMENTED

Report problematic IPs to the abuse IP database

Installation

Install as composer package -- instructions to come.

Step 1. Enable Module

php bin/magento module:enable Cs_AbuseApi

Step 2. Magento setup:upgrade

php bin/magento setup:upgrade

Step 3. Clear cache and compile DI

php bin magento setup:di:compile && php bin/magento cache:flush

Step 4. Update Admin Configuration settings

Update configuration settings in admin: Stores > Configuration > Abuse Api Db

  • Enable module

  • Register For API Key and copy API Key into configuration field

https://www.abuseipdb.com/register

API Key

https://www.abuseipdb.com/register

Register for API Key.


Usage Example

<?phpuseCs\AbuseApi\Model\Service****Client;
//....class Testclass {
private$serviceClient;
//...publicfunction__construct(
ServiceClient$serviceClient
) {
$this->serviceClient = $serviceClient;
}
publicfunctiontestIpCheck($ip) {
return$this->serviceClient->checkIp($ip);
} publicfunctiontestIpsCheck($ips)
{
$collection = $this->serviceClient->checkIps([
'34.87.251.211',
'66.70.157.189',
'144.217.171.225',
'14.178.144.104',
'167.114.90.33',
'188.191.22.226',
'198.27.124.169'
],90);
return$collection;
}
}

Example Output

object(Cs\AbuseApi\Model\Client\CheckResponse)[416]
protected '_data' => array (size=13)
'ipAddress' => string '115.84.92.92' (length=12)
'isPublic' => boolean true
'ipVersion' => int 4
'isWhitelisted' => boolean false
'abuseConfidenceScore' => int 100
'countryCode' => string 'LA' (length=2)
'usageType' => null
'isp' => string 'Telecommunication Service' (length=25)
'domain' => string 'newworldtelecom.net' (length=19)
'hostnames' => array (size=0)
empty
'totalReports' => int 41
'numDistinctUsers' => int 12
'lastReportedAt' => string '2020-09-14T17:23:53+00:00' (length=25)

API Key

https://www.abuseipdb.com/register

account/api

Developer Notes:

Configuration Fields

Base URI => 'base_uri' API Key => 'api_key' Max Days => 'max_days'

Client and HEADERS

<?php$client = newGuzzleHttp\Client([
'base_uri' => 'https://api.abuseipdb.com/api/v2/'
]);
 'headers' => [
'Accept' => 'application/json',
'Key' => $YOUR_API_KEY
],

CHECK Endpoint

Check Parameters

fieldrequireddefaultminmax
ipAddressyes
maxAgeInDaysno301365
verboseno

$response = $client->request('GET', 'check', [ 'query' => [ 'ipAddress' => '118.25.6.39', 'maxAgeInDays' => '90', ],

Request Example

<?php$client = newGuzzleHttp\Client([
'base_uri' => 'https://api.abuseipdb.com/api/v2/'
]);
$response = $client->request('GET', 'check', [
'query' => [
'ipAddress' => '118.25.6.39',
'maxAgeInDays' => '90',
],
'headers' => [
'Accept' => 'application/json',
'Key' => $YOUR_API_KEY
],
]);
$output = $response->getBody();
// Store response as a PHP object.$ipDetails = json_decode($output, true);
?>

Response Example

{
"data": {
"ipAddress": "118.25.6.39",
"isPublic": true,
"ipVersion": 4,
"isWhitelisted": false,
"abuseConfidenceScore": 100,
"countryCode": "CN",
"countryName": "China",
"usageType": "Data Center/Web Hosting/Transit",
"isp": "Tencent Cloud Computing (Beijing) Co. Ltd",
"domain": "tencent.com",
"hostnames": [],
"totalReports": 1,
"numDistinctUsers": 1,
"lastReportedAt": "2018-12-20T20:55:14+00:00",
"reports": [
{
"reportedAt": "2018-12-20T20:55:14+00:00",
"comment": "Dec 20 20:55:14 srv206 sshd[13937]: Invalid user oracle from 118.25.6.39",
"categories": [
18,
22
],
"reporterId": 1,
"reporterCountryCode": "US",
"reporterCountryName": "United States"
}
]
}
}

Categories

IDTitleDescription
1DNS CompromiseAltering DNS records resulting in improper redirection.
2DNS PoisoningFalsifying domain server cache (cache poisoning).
3Fraud OrdersFraudulent orders.
4DDoS AttackParticipating in distributed denial-of-service (usually part of botnet).
5FTP Brute-Force
6Ping of DeathOversized IP packet.
7PhishingPhishing websites and/or email.
8Fraud VoIP
9Open ProxyOpen proxy, open relay, or Tor exit node.
10Web SpamComment/forum spam, HTTP referer spam, or other CMS spam.
11Email SpamSpam email content, infected attachments, and phishing emails. Note: Limit comments to only relevent information (instead of log dumps) and be sure to remove PII if you want to remain anonymous.
12Blog SpamCMS blog comment spam.
13VPN IPConjunctive category.
14Port ScanScanning for open ports and vulnerable services.
15Hacking
16SQL InjectionAttempts at SQL injection.
17SpoofingEmail sender spoofing.
18Brute-ForceCredential brute-force attacks on webpage logins and services like SSH, FTP, SIP, SMTP, RDP, etc. This category is seperate from DDoS attacks.
19Bad Web BotWebpage scraping (for email addresses, content, etc) and crawlers that do not honor robots.txt. Excessive requests and user agent spoofing can also be reported here.
20Exploited HostHost is likely infected with malware and being used for other attacks or to host malicious content. The host owner may not be aware of the compromise. This category is often used in combination with other attack categories.
21Web App AttackAttempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdmin and various other software plugins/solutions.
22SSHSecure Shell (SSH) abuse. Use this category in combination with more specific categories.
23IoT TargetedAbuse was targeted at an "Internet of Things" type device. Include information about what type of device was targeted in the comments.

"1 " => "" Altering DNS records resulting in improper redirection. ", "2 " => "" Falsifying domain server cache (cache poisoning). ", "3 " => "" Fraudulent orders. ", "4 " => "" Participating in distributed denial-of-service (usually part of botnet). ", "5 " => "" ", "6 " => "" Oversized IP packet. ", "7 " => "" Phishing websites and/or email. ", "8 " => "" ", "9 " => "" Open proxy, open relay, or Tor exit node. ", "10" => "Comment/forum spam, HTTP referer spam, or other CMS spam. ", "11" => "Spam email content, infected attachments, and phishing emails. Note: Limit comments to only relevant information (instead of log dumps) and be sure to remove PII if you want to remain anonymous. ", "12" => "CMS blog comment spam. ", "13" => "Conjunctive category. ", "14" => "Scanning for open ports and vulnerable services. ", "15" => "" ", "16" => "Attempts at SQL injection. ", "17" => "Email sender spoofing. ", "18" => "Credential brute-force attacks on webpage logins and services like SSH, FTP, SIP, SMTP, RDP, etc. This category is seperate from DDoS attacks. ", "19" => "Webpage scraping (for email addresses, content, etc) and crawlers that do not honor robots.txt. Excessive requests and user agent spoofing can also be reported here. ", "20" => "Host is likely infected with malware and being used for other attacks or to host malicious content. The host owner may not be aware of the compromise. This category is often used in combination with other attack categories. ", "21" => "Attempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdmin and various other software plugins/solutions. ", "22" => "Secure Shell (SSH) abuse. Use this category in combination with more specific categories. ", "23" => "Abuse was targeted at an "Internet of Things" type device. Include information about what type of device was targeted in the comments. ",

About

Magento2 Abuse IP DB Api Integration

Topics

Resources

Stars

5 stars

Watchers

1 watching

Forks

Releases

Sponsor this project

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

M2 AbuseIPDB API Integration

Url:https://github.com/df2k2/magento2-abuse-api

Author: Chris Snedaker

Date: 2020-06-17


CURRENTLY BEING DEVELOPED

Objective

Create a Magento2 integration to AbuseIPDB API

Website:https://www.abuseipdb.com/

Documentation URL:https://docs.abuseipdb.com/

Unfortunately, too many bots and bad actors are out to take advantage of security flaws.

Purpose

The initial integration will use two different endpoints for:

  • Check IPs
  • Report IPs

Check IPs (https://docs.abuseipdb.com/#check-endpoint)

Use the abuse ip database API to check IPs that seem to be up to no good and take an action based on response to checked IP

Example: https://www.abuseipdb.com/check/115.84.92.92

Below is a chart of problematic IPs attempting to hack/DoS a production magento website in a single day.

ipAddress countryCode isp domain abuseConfidenceScore totalReports
--------- ----------- --- ------ -------------------- ------------
115.84.92.92 LA Telecommunication Service newworldtelecom.net 100 93
34.87.251.211 US Google LLC google.com 100 19
66.70.157.189 CA Kazooisyee ip-66-70-157.net 51 9
144.217.171.225 CA Kazooisyee ip-144-217-171.net 48 9
14.178.144.104 VN Vietnam Posts and Telecommunications Group vnpt.com.vn 46 7
167.114.90.33 CA Kazooisyee ip-167-114-90.net 44 11
188.191.22.226 UA CrimeaCom South LLC crimea-com.net 42 17
198.27.124.169 CA Kazooisyee ip-198-27-124.net 35 11
144.217.99.65 CA Kazooisyee ip-144-217-99.net 34 8
144.217.171.229 CA Kazooisyee ip-144-217-171.net 34 7
216.244.66.197 US Wowrack.com wowrack.com 32 120
66.249.68.25 US Google LLC google.com 22 12
47.244.217.16 HK Alibaba.com LLC alibaba.com 21 3

Report IPs (https://docs.abuseipdb.com/#report-endpoint)

NOT YET IMPLEMENTED

Report problematic IPs to the abuse IP database

Installation

Install as composer package -- instructions to come.

Step 1. Enable Module

php bin/magento module:enable Cs_AbuseApi

Step 2. Magento setup:upgrade

php bin/magento setup:upgrade

Step 3. Clear cache and compile DI

php bin magento setup:di:compile && php bin/magento cache:flush

Step 4. Update Admin Configuration settings

Update configuration settings in admin: Stores > Configuration > Abuse Api Db

  • Enable module

  • Register For API Key and copy API Key into configuration field

https://www.abuseipdb.com/register

API Key

https://www.abuseipdb.com/register

Register for API Key.


Usage Example

<?phpuseCs\AbuseApi\Model\Service****Client;
//....class Testclass {
private$serviceClient;
//...publicfunction__construct(
ServiceClient$serviceClient
) {
$this->serviceClient = $serviceClient;
}
publicfunctiontestIpCheck($ip) {
return$this->serviceClient->checkIp($ip);
} publicfunctiontestIpsCheck($ips)
{
$collection = $this->serviceClient->checkIps([
'34.87.251.211',
'66.70.157.189',
'144.217.171.225',
'14.178.144.104',
'167.114.90.33',
'188.191.22.226',
'198.27.124.169'
],90);
return$collection;
}
}

Example Output

object(Cs\AbuseApi\Model\Client\CheckResponse)[416]
protected '_data' => array (size=13)
'ipAddress' => string '115.84.92.92' (length=12)
'isPublic' => boolean true
'ipVersion' => int 4
'isWhitelisted' => boolean false
'abuseConfidenceScore' => int 100
'countryCode' => string 'LA' (length=2)
'usageType' => null
'isp' => string 'Telecommunication Service' (length=25)
'domain' => string 'newworldtelecom.net' (length=19)
'hostnames' => array (size=0)
empty
'totalReports' => int 41
'numDistinctUsers' => int 12
'lastReportedAt' => string '2020-09-14T17:23:53+00:00' (length=25)

API Key

https://www.abuseipdb.com/register

account/api

Developer Notes:

Configuration Fields

Base URI => 'base_uri' API Key => 'api_key' Max Days => 'max_days'

Client and HEADERS

<?php$client = newGuzzleHttp\Client([
'base_uri' => 'https://api.abuseipdb.com/api/v2/'
]);
 'headers' => [
'Accept' => 'application/json',
'Key' => $YOUR_API_KEY
],

CHECK Endpoint

Check Parameters

fieldrequireddefaultminmax
ipAddressyes
maxAgeInDaysno301365
verboseno

$response = $client->request('GET', 'check', [ 'query' => [ 'ipAddress' => '118.25.6.39', 'maxAgeInDays' => '90', ],

Request Example

<?php$client = newGuzzleHttp\Client([
'base_uri' => 'https://api.abuseipdb.com/api/v2/'
]);
$response = $client->request('GET', 'check', [
'query' => [
'ipAddress' => '118.25.6.39',
'maxAgeInDays' => '90',
],
'headers' => [
'Accept' => 'application/json',
'Key' => $YOUR_API_KEY
],
]);
$output = $response->getBody();
// Store response as a PHP object.$ipDetails = json_decode($output, true);
?>

Response Example

{
"data": {
"ipAddress": "118.25.6.39",
"isPublic": true,
"ipVersion": 4,
"isWhitelisted": false,
"abuseConfidenceScore": 100,
"countryCode": "CN",
"countryName": "China",
"usageType": "Data Center/Web Hosting/Transit",
"isp": "Tencent Cloud Computing (Beijing) Co. Ltd",
"domain": "tencent.com",
"hostnames": [],
"totalReports": 1,
"numDistinctUsers": 1,
"lastReportedAt": "2018-12-20T20:55:14+00:00",
"reports": [
{
"reportedAt": "2018-12-20T20:55:14+00:00",
"comment": "Dec 20 20:55:14 srv206 sshd[13937]: Invalid user oracle from 118.25.6.39",
"categories": [
18,
22
],
"reporterId": 1,
"reporterCountryCode": "US",
"reporterCountryName": "United States"
}
]
}
}

Categories

IDTitleDescription
1DNS CompromiseAltering DNS records resulting in improper redirection.
2DNS PoisoningFalsifying domain server cache (cache poisoning).
3Fraud OrdersFraudulent orders.
4DDoS AttackParticipating in distributed denial-of-service (usually part of botnet).
5FTP Brute-Force
6Ping of DeathOversized IP packet.
7PhishingPhishing websites and/or email.
8Fraud VoIP
9Open ProxyOpen proxy, open relay, or Tor exit node.
10Web SpamComment/forum spam, HTTP referer spam, or other CMS spam.
11Email SpamSpam email content, infected attachments, and phishing emails. Note: Limit comments to only relevent information (instead of log dumps) and be sure to remove PII if you want to remain anonymous.
12Blog SpamCMS blog comment spam.
13VPN IPConjunctive category.
14Port ScanScanning for open ports and vulnerable services.
15Hacking
16SQL InjectionAttempts at SQL injection.
17SpoofingEmail sender spoofing.
18Brute-ForceCredential brute-force attacks on webpage logins and services like SSH, FTP, SIP, SMTP, RDP, etc. This category is seperate from DDoS attacks.
19Bad Web BotWebpage scraping (for email addresses, content, etc) and crawlers that do not honor robots.txt. Excessive requests and user agent spoofing can also be reported here.
20Exploited HostHost is likely infected with malware and being used for other attacks or to host malicious content. The host owner may not be aware of the compromise. This category is often used in combination with other attack categories.
21Web App AttackAttempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdmin and various other software plugins/solutions.
22SSHSecure Shell (SSH) abuse. Use this category in combination with more specific categories.
23IoT TargetedAbuse was targeted at an "Internet of Things" type device. Include information about what type of device was targeted in the comments.

"1 " => "" Altering DNS records resulting in improper redirection. ", "2 " => "" Falsifying domain server cache (cache poisoning). ", "3 " => "" Fraudulent orders. ", "4 " => "" Participating in distributed denial-of-service (usually part of botnet). ", "5 " => "" ", "6 " => "" Oversized IP packet. ", "7 " => "" Phishing websites and/or email. ", "8 " => "" ", "9 " => "" Open proxy, open relay, or Tor exit node. ", "10" => "Comment/forum spam, HTTP referer spam, or other CMS spam. ", "11" => "Spam email content, infected attachments, and phishing emails. Note: Limit comments to only relevant information (instead of log dumps) and be sure to remove PII if you want to remain anonymous. ", "12" => "CMS blog comment spam. ", "13" => "Conjunctive category. ", "14" => "Scanning for open ports and vulnerable services. ", "15" => "" ", "16" => "Attempts at SQL injection. ", "17" => "Email sender spoofing. ", "18" => "Credential brute-force attacks on webpage logins and services like SSH, FTP, SIP, SMTP, RDP, etc. This category is seperate from DDoS attacks. ", "19" => "Webpage scraping (for email addresses, content, etc) and crawlers that do not honor robots.txt. Excessive requests and user agent spoofing can also be reported here. ", "20" => "Host is likely infected with malware and being used for other attacks or to host malicious content. The host owner may not be aware of the compromise. This category is often used in combination with other attack categories. ", "21" => "Attempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdmin and various other software plugins/solutions. ", "22" => "Secure Shell (SSH) abuse. Use this category in combination with more specific categories. ", "23" => "Abuse was targeted at an "Internet of Things" type device. Include information about what type of device was targeted in the comments. ",

About

Magento2 Abuse IP DB Api Integration

Topics

Resources

Stars

5 stars

Watchers

1 watching

Forks

Releases

Sponsor this project

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

M2 AbuseIPDB API Integration

Url:https://github.com/df2k2/magento2-abuse-api

Author: Chris Snedaker

Date: 2020-06-17


CURRENTLY BEING DEVELOPED

Objective

Create a Magento2 integration to AbuseIPDB API

Website:https://www.abuseipdb.com/

Documentation URL:https://docs.abuseipdb.com/

Unfortunately, too many bots and bad actors are out to take advantage of security flaws.

Purpose

The initial integration will use two different endpoints for:

  • Check IPs
  • Report IPs

Check IPs (https://docs.abuseipdb.com/#check-endpoint)

Use the abuse ip database API to check IPs that seem to be up to no good and take an action based on response to checked IP

Example: https://www.abuseipdb.com/check/115.84.92.92

Below is a chart of problematic IPs attempting to hack/DoS a production magento website in a single day.

ipAddress countryCode isp domain abuseConfidenceScore totalReports
--------- ----------- --- ------ -------------------- ------------
115.84.92.92 LA Telecommunication Service newworldtelecom.net 100 93
34.87.251.211 US Google LLC google.com 100 19
66.70.157.189 CA Kazooisyee ip-66-70-157.net 51 9
144.217.171.225 CA Kazooisyee ip-144-217-171.net 48 9
14.178.144.104 VN Vietnam Posts and Telecommunications Group vnpt.com.vn 46 7
167.114.90.33 CA Kazooisyee ip-167-114-90.net 44 11
188.191.22.226 UA CrimeaCom South LLC crimea-com.net 42 17
198.27.124.169 CA Kazooisyee ip-198-27-124.net 35 11
144.217.99.65 CA Kazooisyee ip-144-217-99.net 34 8
144.217.171.229 CA Kazooisyee ip-144-217-171.net 34 7
216.244.66.197 US Wowrack.com wowrack.com 32 120
66.249.68.25 US Google LLC google.com 22 12
47.244.217.16 HK Alibaba.com LLC alibaba.com 21 3

Report IPs (https://docs.abuseipdb.com/#report-endpoint)

NOT YET IMPLEMENTED

Report problematic IPs to the abuse IP database

Installation

Install as composer package -- instructions to come.

Step 1. Enable Module

php bin/magento module:enable Cs_AbuseApi

Step 2. Magento setup:upgrade

php bin/magento setup:upgrade

Step 3. Clear cache and compile DI

php bin magento setup:di:compile && php bin/magento cache:flush

Step 4. Update Admin Configuration settings

Update configuration settings in admin: Stores > Configuration > Abuse Api Db

  • Enable module

  • Register For API Key and copy API Key into configuration field

https://www.abuseipdb.com/register

API Key

https://www.abuseipdb.com/register

Register for API Key.


Usage Example

<?phpuseCs\AbuseApi\Model\Service****Client;
//....class Testclass {
private$serviceClient;
//...publicfunction__construct(
ServiceClient$serviceClient
) {
$this->serviceClient = $serviceClient;
}
publicfunctiontestIpCheck($ip) {
return$this->serviceClient->checkIp($ip);
} publicfunctiontestIpsCheck($ips)
{
$collection = $this->serviceClient->checkIps([
'34.87.251.211',
'66.70.157.189',
'144.217.171.225',
'14.178.144.104',
'167.114.90.33',
'188.191.22.226',
'198.27.124.169'
],90);
return$collection;
}
}

Example Output

object(Cs\AbuseApi\Model\Client\CheckResponse)[416]
protected '_data' => array (size=13)
'ipAddress' => string '115.84.92.92' (length=12)
'isPublic' => boolean true
'ipVersion' => int 4
'isWhitelisted' => boolean false
'abuseConfidenceScore' => int 100
'countryCode' => string 'LA' (length=2)
'usageType' => null
'isp' => string 'Telecommunication Service' (length=25)
'domain' => string 'newworldtelecom.net' (length=19)
'hostnames' => array (size=0)
empty
'totalReports' => int 41
'numDistinctUsers' => int 12
'lastReportedAt' => string '2020-09-14T17:23:53+00:00' (length=25)

API Key

https://www.abuseipdb.com/register

account/api

Developer Notes:

Configuration Fields

Base URI => 'base_uri' API Key => 'api_key' Max Days => 'max_days'

Client and HEADERS

<?php$client = newGuzzleHttp\Client([
'base_uri' => 'https://api.abuseipdb.com/api/v2/'
]);
 'headers' => [
'Accept' => 'application/json',
'Key' => $YOUR_API_KEY
],

CHECK Endpoint

Check Parameters

fieldrequireddefaultminmax
ipAddressyes
maxAgeInDaysno301365
verboseno

$response = $client->request('GET', 'check', [ 'query' => [ 'ipAddress' => '118.25.6.39', 'maxAgeInDays' => '90', ],

Request Example

<?php$client = newGuzzleHttp\Client([
'base_uri' => 'https://api.abuseipdb.com/api/v2/'
]);
$response = $client->request('GET', 'check', [
'query' => [
'ipAddress' => '118.25.6.39',
'maxAgeInDays' => '90',
],
'headers' => [
'Accept' => 'application/json',
'Key' => $YOUR_API_KEY
],
]);
$output = $response->getBody();
// Store response as a PHP object.$ipDetails = json_decode($output, true);
?>

Response Example

{
"data": {
"ipAddress": "118.25.6.39",
"isPublic": true,
"ipVersion": 4,
"isWhitelisted": false,
"abuseConfidenceScore": 100,
"countryCode": "CN",
"countryName": "China",
"usageType": "Data Center/Web Hosting/Transit",
"isp": "Tencent Cloud Computing (Beijing) Co. Ltd",
"domain": "tencent.com",
"hostnames": [],
"totalReports": 1,
"numDistinctUsers": 1,
"lastReportedAt": "2018-12-20T20:55:14+00:00",
"reports": [
{
"reportedAt": "2018-12-20T20:55:14+00:00",
"comment": "Dec 20 20:55:14 srv206 sshd[13937]: Invalid user oracle from 118.25.6.39",
"categories": [
18,
22
],
"reporterId": 1,
"reporterCountryCode": "US",
"reporterCountryName": "United States"
}
]
}
}

Categories

IDTitleDescription
1DNS CompromiseAltering DNS records resulting in improper redirection.
2DNS PoisoningFalsifying domain server cache (cache poisoning).
3Fraud OrdersFraudulent orders.
4DDoS AttackParticipating in distributed denial-of-service (usually part of botnet).
5FTP Brute-Force
6Ping of DeathOversized IP packet.
7PhishingPhishing websites and/or email.
8Fraud VoIP
9Open ProxyOpen proxy, open relay, or Tor exit node.
10Web SpamComment/forum spam, HTTP referer spam, or other CMS spam.
11Email SpamSpam email content, infected attachments, and phishing emails. Note: Limit comments to only relevent information (instead of log dumps) and be sure to remove PII if you want to remain anonymous.
12Blog SpamCMS blog comment spam.
13VPN IPConjunctive category.
14Port ScanScanning for open ports and vulnerable services.
15Hacking
16SQL InjectionAttempts at SQL injection.
17SpoofingEmail sender spoofing.
18Brute-ForceCredential brute-force attacks on webpage logins and services like SSH, FTP, SIP, SMTP, RDP, etc. This category is seperate from DDoS attacks.
19Bad Web BotWebpage scraping (for email addresses, content, etc) and crawlers that do not honor robots.txt. Excessive requests and user agent spoofing can also be reported here.
20Exploited HostHost is likely infected with malware and being used for other attacks or to host malicious content. The host owner may not be aware of the compromise. This category is often used in combination with other attack categories.
21Web App AttackAttempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdmin and various other software plugins/solutions.
22SSHSecure Shell (SSH) abuse. Use this category in combination with more specific categories.
23IoT TargetedAbuse was targeted at an "Internet of Things" type device. Include information about what type of device was targeted in the comments.

"1 " => "" Altering DNS records resulting in improper redirection. ", "2 " => "" Falsifying domain server cache (cache poisoning). ", "3 " => "" Fraudulent orders. ", "4 " => "" Participating in distributed denial-of-service (usually part of botnet). ", "5 " => "" ", "6 " => "" Oversized IP packet. ", "7 " => "" Phishing websites and/or email. ", "8 " => "" ", "9 " => "" Open proxy, open relay, or Tor exit node. ", "10" => "Comment/forum spam, HTTP referer spam, or other CMS spam. ", "11" => "Spam email content, infected attachments, and phishing emails. Note: Limit comments to only relevant information (instead of log dumps) and be sure to remove PII if you want to remain anonymous. ", "12" => "CMS blog comment spam. ", "13" => "Conjunctive category. ", "14" => "Scanning for open ports and vulnerable services. ", "15" => "" ", "16" => "Attempts at SQL injection. ", "17" => "Email sender spoofing. ", "18" => "Credential brute-force attacks on webpage logins and services like SSH, FTP, SIP, SMTP, RDP, etc. This category is seperate from DDoS attacks. ", "19" => "Webpage scraping (for email addresses, content, etc) and crawlers that do not honor robots.txt. Excessive requests and user agent spoofing can also be reported here. ", "20" => "Host is likely infected with malware and being used for other attacks or to host malicious content. The host owner may not be aware of the compromise. This category is often used in combination with other attack categories. ", "21" => "Attempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdmin and various other software plugins/solutions. ", "22" => "Secure Shell (SSH) abuse. Use this category in combination with more specific categories. ", "23" => "Abuse was targeted at an "Internet of Things" type device. Include information about what type of device was targeted in the comments. ",

About

Magento2 Abuse IP DB Api Integration

Topics

Resources

Stars

5 stars

Watchers

1 watching

Forks

Releases

Sponsor this project

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

M2 AbuseIPDB API Integration

Url:https://github.com/df2k2/magento2-abuse-api

Author: Chris Snedaker

Date: 2020-06-17


CURRENTLY BEING DEVELOPED

Objective

Create a Magento2 integration to AbuseIPDB API

Website:https://www.abuseipdb.com/

Documentation URL:https://docs.abuseipdb.com/

Unfortunately, too many bots and bad actors are out to take advantage of security flaws.

Purpose

The initial integration will use two different endpoints for:

  • Check IPs
  • Report IPs

Check IPs (https://docs.abuseipdb.com/#check-endpoint)

Use the abuse ip database API to check IPs that seem to be up to no good and take an action based on response to checked IP

Example: https://www.abuseipdb.com/check/115.84.92.92

Below is a chart of problematic IPs attempting to hack/DoS a production magento website in a single day.

ipAddress countryCode isp domain abuseConfidenceScore totalReports
--------- ----------- --- ------ -------------------- ------------
115.84.92.92 LA Telecommunication Service newworldtelecom.net 100 93
34.87.251.211 US Google LLC google.com 100 19
66.70.157.189 CA Kazooisyee ip-66-70-157.net 51 9
144.217.171.225 CA Kazooisyee ip-144-217-171.net 48 9
14.178.144.104 VN Vietnam Posts and Telecommunications Group vnpt.com.vn 46 7
167.114.90.33 CA Kazooisyee ip-167-114-90.net 44 11
188.191.22.226 UA CrimeaCom South LLC crimea-com.net 42 17
198.27.124.169 CA Kazooisyee ip-198-27-124.net 35 11
144.217.99.65 CA Kazooisyee ip-144-217-99.net 34 8
144.217.171.229 CA Kazooisyee ip-144-217-171.net 34 7
216.244.66.197 US Wowrack.com wowrack.com 32 120
66.249.68.25 US Google LLC google.com 22 12
47.244.217.16 HK Alibaba.com LLC alibaba.com 21 3

Report IPs (https://docs.abuseipdb.com/#report-endpoint)

NOT YET IMPLEMENTED

Report problematic IPs to the abuse IP database

Installation

Install as composer package -- instructions to come.

Step 1. Enable Module

php bin/magento module:enable Cs_AbuseApi

Step 2. Magento setup:upgrade

php bin/magento setup:upgrade

Step 3. Clear cache and compile DI

php bin magento setup:di:compile && php bin/magento cache:flush

Step 4. Update Admin Configuration settings

Update configuration settings in admin: Stores > Configuration > Abuse Api Db

  • Enable module

  • Register For API Key and copy API Key into configuration field

https://www.abuseipdb.com/register

API Key

https://www.abuseipdb.com/register

Register for API Key.


Usage Example

<?phpuseCs\AbuseApi\Model\Service****Client;
//....class Testclass {
private$serviceClient;
//...publicfunction__construct(
ServiceClient$serviceClient
) {
$this->serviceClient = $serviceClient;
}
publicfunctiontestIpCheck($ip) {
return$this->serviceClient->checkIp($ip);
} publicfunctiontestIpsCheck($ips)
{
$collection = $this->serviceClient->checkIps([
'34.87.251.211',
'66.70.157.189',
'144.217.171.225',
'14.178.144.104',
'167.114.90.33',
'188.191.22.226',
'198.27.124.169'
],90);
return$collection;
}
}

Example Output

object(Cs\AbuseApi\Model\Client\CheckResponse)[416]
protected '_data' => array (size=13)
'ipAddress' => string '115.84.92.92' (length=12)
'isPublic' => boolean true
'ipVersion' => int 4
'isWhitelisted' => boolean false
'abuseConfidenceScore' => int 100
'countryCode' => string 'LA' (length=2)
'usageType' => null
'isp' => string 'Telecommunication Service' (length=25)
'domain' => string 'newworldtelecom.net' (length=19)
'hostnames' => array (size=0)
empty
'totalReports' => int 41
'numDistinctUsers' => int 12
'lastReportedAt' => string '2020-09-14T17:23:53+00:00' (length=25)

API Key

https://www.abuseipdb.com/register

account/api

Developer Notes:

Configuration Fields

Base URI => 'base_uri' API Key => 'api_key' Max Days => 'max_days'

Client and HEADERS

<?php$client = newGuzzleHttp\Client([
'base_uri' => 'https://api.abuseipdb.com/api/v2/'
]);
 'headers' => [
'Accept' => 'application/json',
'Key' => $YOUR_API_KEY
],

CHECK Endpoint

Check Parameters

fieldrequireddefaultminmax
ipAddressyes
maxAgeInDaysno301365
verboseno

$response = $client->request('GET', 'check', [ 'query' => [ 'ipAddress' => '118.25.6.39', 'maxAgeInDays' => '90', ],

Request Example

<?php$client = newGuzzleHttp\Client([
'base_uri' => 'https://api.abuseipdb.com/api/v2/'
]);
$response = $client->request('GET', 'check', [
'query' => [
'ipAddress' => '118.25.6.39',
'maxAgeInDays' => '90',
],
'headers' => [
'Accept' => 'application/json',
'Key' => $YOUR_API_KEY
],
]);
$output = $response->getBody();
// Store response as a PHP object.$ipDetails = json_decode($output, true);
?>

Response Example

{
"data": {
"ipAddress": "118.25.6.39",
"isPublic": true,
"ipVersion": 4,
"isWhitelisted": false,
"abuseConfidenceScore": 100,
"countryCode": "CN",
"countryName": "China",
"usageType": "Data Center/Web Hosting/Transit",
"isp": "Tencent Cloud Computing (Beijing) Co. Ltd",
"domain": "tencent.com",
"hostnames": [],
"totalReports": 1,
"numDistinctUsers": 1,
"lastReportedAt": "2018-12-20T20:55:14+00:00",
"reports": [
{
"reportedAt": "2018-12-20T20:55:14+00:00",
"comment": "Dec 20 20:55:14 srv206 sshd[13937]: Invalid user oracle from 118.25.6.39",
"categories": [
18,
22
],
"reporterId": 1,
"reporterCountryCode": "US",
"reporterCountryName": "United States"
}
]
}
}

Categories

IDTitleDescription
1DNS CompromiseAltering DNS records resulting in improper redirection.
2DNS PoisoningFalsifying domain server cache (cache poisoning).
3Fraud OrdersFraudulent orders.
4DDoS AttackParticipating in distributed denial-of-service (usually part of botnet).
5FTP Brute-Force
6Ping of DeathOversized IP packet.
7PhishingPhishing websites and/or email.
8Fraud VoIP
9Open ProxyOpen proxy, open relay, or Tor exit node.
10Web SpamComment/forum spam, HTTP referer spam, or other CMS spam.
11Email SpamSpam email content, infected attachments, and phishing emails. Note: Limit comments to only relevent information (instead of log dumps) and be sure to remove PII if you want to remain anonymous.
12Blog SpamCMS blog comment spam.
13VPN IPConjunctive category.
14Port ScanScanning for open ports and vulnerable services.
15Hacking
16SQL InjectionAttempts at SQL injection.
17SpoofingEmail sender spoofing.
18Brute-ForceCredential brute-force attacks on webpage logins and services like SSH, FTP, SIP, SMTP, RDP, etc. This category is seperate from DDoS attacks.
19Bad Web BotWebpage scraping (for email addresses, content, etc) and crawlers that do not honor robots.txt. Excessive requests and user agent spoofing can also be reported here.
20Exploited HostHost is likely infected with malware and being used for other attacks or to host malicious content. The host owner may not be aware of the compromise. This category is often used in combination with other attack categories.
21Web App AttackAttempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdmin and various other software plugins/solutions.
22SSHSecure Shell (SSH) abuse. Use this category in combination with more specific categories.
23IoT TargetedAbuse was targeted at an "Internet of Things" type device. Include information about what type of device was targeted in the comments.

"1 " => "" Altering DNS records resulting in improper redirection. ", "2 " => "" Falsifying domain server cache (cache poisoning). ", "3 " => "" Fraudulent orders. ", "4 " => "" Participating in distributed denial-of-service (usually part of botnet). ", "5 " => "" ", "6 " => "" Oversized IP packet. ", "7 " => "" Phishing websites and/or email. ", "8 " => "" ", "9 " => "" Open proxy, open relay, or Tor exit node. ", "10" => "Comment/forum spam, HTTP referer spam, or other CMS spam. ", "11" => "Spam email content, infected attachments, and phishing emails. Note: Limit comments to only relevant information (instead of log dumps) and be sure to remove PII if you want to remain anonymous. ", "12" => "CMS blog comment spam. ", "13" => "Conjunctive category. ", "14" => "Scanning for open ports and vulnerable services. ", "15" => "" ", "16" => "Attempts at SQL injection. ", "17" => "Email sender spoofing. ", "18" => "Credential brute-force attacks on webpage logins and services like SSH, FTP, SIP, SMTP, RDP, etc. This category is seperate from DDoS attacks. ", "19" => "Webpage scraping (for email addresses, content, etc) and crawlers that do not honor robots.txt. Excessive requests and user agent spoofing can also be reported here. ", "20" => "Host is likely infected with malware and being used for other attacks or to host malicious content. The host owner may not be aware of the compromise. This category is often used in combination with other attack categories. ", "21" => "Attempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdmin and various other software plugins/solutions. ", "22" => "Secure Shell (SSH) abuse. Use this category in combination with more specific categories. ", "23" => "Abuse was targeted at an "Internet of Things" type device. Include information about what type of device was targeted in the comments. ",

About

Magento2 Abuse IP DB Api Integration

Topics

Resources

Stars

5 stars

Watchers

1 watching

Forks

Releases

Sponsor this project

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

M2 AbuseIPDB API Integration

Url:https://github.com/df2k2/magento2-abuse-api

Author: Chris Snedaker

Date: 2020-06-17


CURRENTLY BEING DEVELOPED

Objective

Create a Magento2 integration to AbuseIPDB API

Website:https://www.abuseipdb.com/

Documentation URL:https://docs.abuseipdb.com/

Unfortunately, too many bots and bad actors are out to take advantage of security flaws.

Purpose

The initial integration will use two different endpoints for:

  • Check IPs
  • Report IPs

Check IPs (https://docs.abuseipdb.com/#check-endpoint)

Use the abuse ip database API to check IPs that seem to be up to no good and take an action based on response to checked IP

Example: https://www.abuseipdb.com/check/115.84.92.92

Below is a chart of problematic IPs attempting to hack/DoS a production magento website in a single day.

ipAddress countryCode isp domain abuseConfidenceScore totalReports
--------- ----------- --- ------ -------------------- ------------
115.84.92.92 LA Telecommunication Service newworldtelecom.net 100 93
34.87.251.211 US Google LLC google.com 100 19
66.70.157.189 CA Kazooisyee ip-66-70-157.net 51 9
144.217.171.225 CA Kazooisyee ip-144-217-171.net 48 9
14.178.144.104 VN Vietnam Posts and Telecommunications Group vnpt.com.vn 46 7
167.114.90.33 CA Kazooisyee ip-167-114-90.net 44 11
188.191.22.226 UA CrimeaCom South LLC crimea-com.net 42 17
198.27.124.169 CA Kazooisyee ip-198-27-124.net 35 11
144.217.99.65 CA Kazooisyee ip-144-217-99.net 34 8
144.217.171.229 CA Kazooisyee ip-144-217-171.net 34 7
216.244.66.197 US Wowrack.com wowrack.com 32 120
66.249.68.25 US Google LLC google.com 22 12
47.244.217.16 HK Alibaba.com LLC alibaba.com 21 3

Report IPs (https://docs.abuseipdb.com/#report-endpoint)

NOT YET IMPLEMENTED

Report problematic IPs to the abuse IP database

Installation

Install as composer package -- instructions to come.

Step 1. Enable Module

php bin/magento module:enable Cs_AbuseApi

Step 2. Magento setup:upgrade

php bin/magento setup:upgrade

Step 3. Clear cache and compile DI

php bin magento setup:di:compile && php bin/magento cache:flush

Step 4. Update Admin Configuration settings

Update configuration settings in admin: Stores > Configuration > Abuse Api Db

  • Enable module

  • Register For API Key and copy API Key into configuration field

https://www.abuseipdb.com/register

API Key

https://www.abuseipdb.com/register

Register for API Key.


Usage Example

<?phpuseCs\AbuseApi\Model\Service****Client;
//....class Testclass {
private$serviceClient;
//...publicfunction__construct(
ServiceClient$serviceClient
) {
$this->serviceClient = $serviceClient;
}
publicfunctiontestIpCheck($ip) {
return$this->serviceClient->checkIp($ip);
} publicfunctiontestIpsCheck($ips)
{
$collection = $this->serviceClient->checkIps([
'34.87.251.211',
'66.70.157.189',
'144.217.171.225',
'14.178.144.104',
'167.114.90.33',
'188.191.22.226',
'198.27.124.169'
],90);
return$collection;
}
}

Example Output

object(Cs\AbuseApi\Model\Client\CheckResponse)[416]
protected '_data' => array (size=13)
'ipAddress' => string '115.84.92.92' (length=12)
'isPublic' => boolean true
'ipVersion' => int 4
'isWhitelisted' => boolean false
'abuseConfidenceScore' => int 100
'countryCode' => string 'LA' (length=2)
'usageType' => null
'isp' => string 'Telecommunication Service' (length=25)
'domain' => string 'newworldtelecom.net' (length=19)
'hostnames' => array (size=0)
empty
'totalReports' => int 41
'numDistinctUsers' => int 12
'lastReportedAt' => string '2020-09-14T17:23:53+00:00' (length=25)

API Key

https://www.abuseipdb.com/register

account/api

Developer Notes:

Configuration Fields

Base URI => 'base_uri' API Key => 'api_key' Max Days => 'max_days'

Client and HEADERS

<?php$client = newGuzzleHttp\Client([
'base_uri' => 'https://api.abuseipdb.com/api/v2/'
]);
 'headers' => [
'Accept' => 'application/json',
'Key' => $YOUR_API_KEY
],

CHECK Endpoint

Check Parameters

fieldrequireddefaultminmax
ipAddressyes
maxAgeInDaysno301365
verboseno

$response = $client->request('GET', 'check', [ 'query' => [ 'ipAddress' => '118.25.6.39', 'maxAgeInDays' => '90', ],

Request Example

<?php$client = newGuzzleHttp\Client([
'base_uri' => 'https://api.abuseipdb.com/api/v2/'
]);
$response = $client->request('GET', 'check', [
'query' => [
'ipAddress' => '118.25.6.39',
'maxAgeInDays' => '90',
],
'headers' => [
'Accept' => 'application/json',
'Key' => $YOUR_API_KEY
],
]);
$output = $response->getBody();
// Store response as a PHP object.$ipDetails = json_decode($output, true);
?>

Response Example

{
"data": {
"ipAddress": "118.25.6.39",
"isPublic": true,
"ipVersion": 4,
"isWhitelisted": false,
"abuseConfidenceScore": 100,
"countryCode": "CN",
"countryName": "China",
"usageType": "Data Center/Web Hosting/Transit",
"isp": "Tencent Cloud Computing (Beijing) Co. Ltd",
"domain": "tencent.com",
"hostnames": [],
"totalReports": 1,
"numDistinctUsers": 1,
"lastReportedAt": "2018-12-20T20:55:14+00:00",
"reports": [
{
"reportedAt": "2018-12-20T20:55:14+00:00",
"comment": "Dec 20 20:55:14 srv206 sshd[13937]: Invalid user oracle from 118.25.6.39",
"categories": [
18,
22
],
"reporterId": 1,
"reporterCountryCode": "US",
"reporterCountryName": "United States"
}
]
}
}

Categories

IDTitleDescription
1DNS CompromiseAltering DNS records resulting in improper redirection.
2DNS PoisoningFalsifying domain server cache (cache poisoning).
3Fraud OrdersFraudulent orders.
4DDoS AttackParticipating in distributed denial-of-service (usually part of botnet).
5FTP Brute-Force
6Ping of DeathOversized IP packet.
7PhishingPhishing websites and/or email.
8Fraud VoIP
9Open ProxyOpen proxy, open relay, or Tor exit node.
10Web SpamComment/forum spam, HTTP referer spam, or other CMS spam.
11Email SpamSpam email content, infected attachments, and phishing emails. Note: Limit comments to only relevent information (instead of log dumps) and be sure to remove PII if you want to remain anonymous.
12Blog SpamCMS blog comment spam.
13VPN IPConjunctive category.
14Port ScanScanning for open ports and vulnerable services.
15Hacking
16SQL InjectionAttempts at SQL injection.
17SpoofingEmail sender spoofing.
18Brute-ForceCredential brute-force attacks on webpage logins and services like SSH, FTP, SIP, SMTP, RDP, etc. This category is seperate from DDoS attacks.
19Bad Web BotWebpage scraping (for email addresses, content, etc) and crawlers that do not honor robots.txt. Excessive requests and user agent spoofing can also be reported here.
20Exploited HostHost is likely infected with malware and being used for other attacks or to host malicious content. The host owner may not be aware of the compromise. This category is often used in combination with other attack categories.
21Web App AttackAttempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdmin and various other software plugins/solutions.
22SSHSecure Shell (SSH) abuse. Use this category in combination with more specific categories.
23IoT TargetedAbuse was targeted at an "Internet of Things" type device. Include information about what type of device was targeted in the comments.

"1 " => "" Altering DNS records resulting in improper redirection. ", "2 " => "" Falsifying domain server cache (cache poisoning). ", "3 " => "" Fraudulent orders. ", "4 " => "" Participating in distributed denial-of-service (usually part of botnet). ", "5 " => "" ", "6 " => "" Oversized IP packet. ", "7 " => "" Phishing websites and/or email. ", "8 " => "" ", "9 " => "" Open proxy, open relay, or Tor exit node. ", "10" => "Comment/forum spam, HTTP referer spam, or other CMS spam. ", "11" => "Spam email content, infected attachments, and phishing emails. Note: Limit comments to only relevant information (instead of log dumps) and be sure to remove PII if you want to remain anonymous. ", "12" => "CMS blog comment spam. ", "13" => "Conjunctive category. ", "14" => "Scanning for open ports and vulnerable services. ", "15" => "" ", "16" => "Attempts at SQL injection. ", "17" => "Email sender spoofing. ", "18" => "Credential brute-force attacks on webpage logins and services like SSH, FTP, SIP, SMTP, RDP, etc. This category is seperate from DDoS attacks. ", "19" => "Webpage scraping (for email addresses, content, etc) and crawlers that do not honor robots.txt. Excessive requests and user agent spoofing can also be reported here. ", "20" => "Host is likely infected with malware and being used for other attacks or to host malicious content. The host owner may not be aware of the compromise. This category is often used in combination with other attack categories. ", "21" => "Attempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdmin and various other software plugins/solutions. ", "22" => "Secure Shell (SSH) abuse. Use this category in combination with more specific categories. ", "23" => "Abuse was targeted at an "Internet of Things" type device. Include information about what type of device was targeted in the comments. ",

About

Magento2 Abuse IP DB Api Integration

Topics

Resources

Stars

5 stars

Watchers

1 watching

Forks

Releases

Sponsor this project

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

M2 AbuseIPDB API Integration

Url:https://github.com/df2k2/magento2-abuse-api

Author: Chris Snedaker

Date: 2020-06-17


CURRENTLY BEING DEVELOPED

Objective

Create a Magento2 integration to AbuseIPDB API

Website:https://www.abuseipdb.com/

Documentation URL:https://docs.abuseipdb.com/

Unfortunately, too many bots and bad actors are out to take advantage of security flaws.

Purpose

The initial integration will use two different endpoints for:

  • Check IPs
  • Report IPs

Check IPs (https://docs.abuseipdb.com/#check-endpoint)

Use the abuse ip database API to check IPs that seem to be up to no good and take an action based on response to checked IP

Example: https://www.abuseipdb.com/check/115.84.92.92

Below is a chart of problematic IPs attempting to hack/DoS a production magento website in a single day.

ipAddress countryCode isp domain abuseConfidenceScore totalReports
--------- ----------- --- ------ -------------------- ------------
115.84.92.92 LA Telecommunication Service newworldtelecom.net 100 93
34.87.251.211 US Google LLC google.com 100 19
66.70.157.189 CA Kazooisyee ip-66-70-157.net 51 9
144.217.171.225 CA Kazooisyee ip-144-217-171.net 48 9
14.178.144.104 VN Vietnam Posts and Telecommunications Group vnpt.com.vn 46 7
167.114.90.33 CA Kazooisyee ip-167-114-90.net 44 11
188.191.22.226 UA CrimeaCom South LLC crimea-com.net 42 17
198.27.124.169 CA Kazooisyee ip-198-27-124.net 35 11
144.217.99.65 CA Kazooisyee ip-144-217-99.net 34 8
144.217.171.229 CA Kazooisyee ip-144-217-171.net 34 7
216.244.66.197 US Wowrack.com wowrack.com 32 120
66.249.68.25 US Google LLC google.com 22 12
47.244.217.16 HK Alibaba.com LLC alibaba.com 21 3

Report IPs (https://docs.abuseipdb.com/#report-endpoint)

NOT YET IMPLEMENTED

Report problematic IPs to the abuse IP database

Installation

Install as composer package -- instructions to come.

Step 1. Enable Module

php bin/magento module:enable Cs_AbuseApi

Step 2. Magento setup:upgrade

php bin/magento setup:upgrade

Step 3. Clear cache and compile DI

php bin magento setup:di:compile && php bin/magento cache:flush

Step 4. Update Admin Configuration settings

Update configuration settings in admin: Stores > Configuration > Abuse Api Db

  • Enable module

  • Register For API Key and copy API Key into configuration field

https://www.abuseipdb.com/register

API Key

https://www.abuseipdb.com/register

Register for API Key.


Usage Example

<?phpuseCs\AbuseApi\Model\Service****Client;
//....class Testclass {
private$serviceClient;
//...publicfunction__construct(
ServiceClient$serviceClient
) {
$this->serviceClient = $serviceClient;
}
publicfunctiontestIpCheck($ip) {
return$this->serviceClient->checkIp($ip);
} publicfunctiontestIpsCheck($ips)
{
$collection = $this->serviceClient->checkIps([
'34.87.251.211',
'66.70.157.189',
'144.217.171.225',
'14.178.144.104',
'167.114.90.33',
'188.191.22.226',
'198.27.124.169'
],90);
return$collection;
}
}

Example Output

object(Cs\AbuseApi\Model\Client\CheckResponse)[416]
protected '_data' => array (size=13)
'ipAddress' => string '115.84.92.92' (length=12)
'isPublic' => boolean true
'ipVersion' => int 4
'isWhitelisted' => boolean false
'abuseConfidenceScore' => int 100
'countryCode' => string 'LA' (length=2)
'usageType' => null
'isp' => string 'Telecommunication Service' (length=25)
'domain' => string 'newworldtelecom.net' (length=19)
'hostnames' => array (size=0)
empty
'totalReports' => int 41
'numDistinctUsers' => int 12
'lastReportedAt' => string '2020-09-14T17:23:53+00:00' (length=25)

API Key

https://www.abuseipdb.com/register

account/api

Developer Notes:

Configuration Fields

Base URI => 'base_uri' API Key => 'api_key' Max Days => 'max_days'

Client and HEADERS

<?php$client = newGuzzleHttp\Client([
'base_uri' => 'https://api.abuseipdb.com/api/v2/'
]);
 'headers' => [
'Accept' => 'application/json',
'Key' => $YOUR_API_KEY
],

CHECK Endpoint

Check Parameters

fieldrequireddefaultminmax
ipAddressyes
maxAgeInDaysno301365
verboseno

$response = $client->request('GET', 'check', [ 'query' => [ 'ipAddress' => '118.25.6.39', 'maxAgeInDays' => '90', ],

Request Example

<?php$client = newGuzzleHttp\Client([
'base_uri' => 'https://api.abuseipdb.com/api/v2/'
]);
$response = $client->request('GET', 'check', [
'query' => [
'ipAddress' => '118.25.6.39',
'maxAgeInDays' => '90',
],
'headers' => [
'Accept' => 'application/json',
'Key' => $YOUR_API_KEY
],
]);
$output = $response->getBody();
// Store response as a PHP object.$ipDetails = json_decode($output, true);
?>

Response Example

{
"data": {
"ipAddress": "118.25.6.39",
"isPublic": true,
"ipVersion": 4,
"isWhitelisted": false,
"abuseConfidenceScore": 100,
"countryCode": "CN",
"countryName": "China",
"usageType": "Data Center/Web Hosting/Transit",
"isp": "Tencent Cloud Computing (Beijing) Co. Ltd",
"domain": "tencent.com",
"hostnames": [],
"totalReports": 1,
"numDistinctUsers": 1,
"lastReportedAt": "2018-12-20T20:55:14+00:00",
"reports": [
{
"reportedAt": "2018-12-20T20:55:14+00:00",
"comment": "Dec 20 20:55:14 srv206 sshd[13937]: Invalid user oracle from 118.25.6.39",
"categories": [
18,
22
],
"reporterId": 1,
"reporterCountryCode": "US",
"reporterCountryName": "United States"
}
]
}
}

Categories

IDTitleDescription
1DNS CompromiseAltering DNS records resulting in improper redirection.
2DNS PoisoningFalsifying domain server cache (cache poisoning).
3Fraud OrdersFraudulent orders.
4DDoS AttackParticipating in distributed denial-of-service (usually part of botnet).
5FTP Brute-Force
6Ping of DeathOversized IP packet.
7PhishingPhishing websites and/or email.
8Fraud VoIP
9Open ProxyOpen proxy, open relay, or Tor exit node.
10Web SpamComment/forum spam, HTTP referer spam, or other CMS spam.
11Email SpamSpam email content, infected attachments, and phishing emails. Note: Limit comments to only relevent information (instead of log dumps) and be sure to remove PII if you want to remain anonymous.
12Blog SpamCMS blog comment spam.
13VPN IPConjunctive category.
14Port ScanScanning for open ports and vulnerable services.
15Hacking
16SQL InjectionAttempts at SQL injection.
17SpoofingEmail sender spoofing.
18Brute-ForceCredential brute-force attacks on webpage logins and services like SSH, FTP, SIP, SMTP, RDP, etc. This category is seperate from DDoS attacks.
19Bad Web BotWebpage scraping (for email addresses, content, etc) and crawlers that do not honor robots.txt. Excessive requests and user agent spoofing can also be reported here.
20Exploited HostHost is likely infected with malware and being used for other attacks or to host malicious content. The host owner may not be aware of the compromise. This category is often used in combination with other attack categories.
21Web App AttackAttempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdmin and various other software plugins/solutions.
22SSHSecure Shell (SSH) abuse. Use this category in combination with more specific categories.
23IoT TargetedAbuse was targeted at an "Internet of Things" type device. Include information about what type of device was targeted in the comments.

"1 " => "" Altering DNS records resulting in improper redirection. ", "2 " => "" Falsifying domain server cache (cache poisoning). ", "3 " => "" Fraudulent orders. ", "4 " => "" Participating in distributed denial-of-service (usually part of botnet). ", "5 " => "" ", "6 " => "" Oversized IP packet. ", "7 " => "" Phishing websites and/or email. ", "8 " => "" ", "9 " => "" Open proxy, open relay, or Tor exit node. ", "10" => "Comment/forum spam, HTTP referer spam, or other CMS spam. ", "11" => "Spam email content, infected attachments, and phishing emails. Note: Limit comments to only relevant information (instead of log dumps) and be sure to remove PII if you want to remain anonymous. ", "12" => "CMS blog comment spam. ", "13" => "Conjunctive category. ", "14" => "Scanning for open ports and vulnerable services. ", "15" => "" ", "16" => "Attempts at SQL injection. ", "17" => "Email sender spoofing. ", "18" => "Credential brute-force attacks on webpage logins and services like SSH, FTP, SIP, SMTP, RDP, etc. This category is seperate from DDoS attacks. ", "19" => "Webpage scraping (for email addresses, content, etc) and crawlers that do not honor robots.txt. Excessive requests and user agent spoofing can also be reported here. ", "20" => "Host is likely infected with malware and being used for other attacks or to host malicious content. The host owner may not be aware of the compromise. This category is often used in combination with other attack categories. ", "21" => "Attempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdmin and various other software plugins/solutions. ", "22" => "Secure Shell (SSH) abuse. Use this category in combination with more specific categories. ", "23" => "Abuse was targeted at an "Internet of Things" type device. Include information about what type of device was targeted in the comments. ",

About

Magento2 Abuse IP DB Api Integration

Topics

Resources

Stars

5 stars

Watchers

1 watching

Forks

Releases

Sponsor this project

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

M2 AbuseIPDB API Integration

Url:https://github.com/df2k2/magento2-abuse-api

Author: Chris Snedaker

Date: 2020-06-17


CURRENTLY BEING DEVELOPED

Objective

Create a Magento2 integration to AbuseIPDB API

Website:https://www.abuseipdb.com/

Documentation URL:https://docs.abuseipdb.com/

Unfortunately, too many bots and bad actors are out to take advantage of security flaws.

Purpose

The initial integration will use two different endpoints for:

  • Check IPs
  • Report IPs

Check IPs (https://docs.abuseipdb.com/#check-endpoint)

Use the abuse ip database API to check IPs that seem to be up to no good and take an action based on response to checked IP

Example: https://www.abuseipdb.com/check/115.84.92.92

Below is a chart of problematic IPs attempting to hack/DoS a production magento website in a single day.

ipAddress countryCode isp domain abuseConfidenceScore totalReports
--------- ----------- --- ------ -------------------- ------------
115.84.92.92 LA Telecommunication Service newworldtelecom.net 100 93
34.87.251.211 US Google LLC google.com 100 19
66.70.157.189 CA Kazooisyee ip-66-70-157.net 51 9
144.217.171.225 CA Kazooisyee ip-144-217-171.net 48 9
14.178.144.104 VN Vietnam Posts and Telecommunications Group vnpt.com.vn 46 7
167.114.90.33 CA Kazooisyee ip-167-114-90.net 44 11
188.191.22.226 UA CrimeaCom South LLC crimea-com.net 42 17
198.27.124.169 CA Kazooisyee ip-198-27-124.net 35 11
144.217.99.65 CA Kazooisyee ip-144-217-99.net 34 8
144.217.171.229 CA Kazooisyee ip-144-217-171.net 34 7
216.244.66.197 US Wowrack.com wowrack.com 32 120
66.249.68.25 US Google LLC google.com 22 12
47.244.217.16 HK Alibaba.com LLC alibaba.com 21 3

Report IPs (https://docs.abuseipdb.com/#report-endpoint)

NOT YET IMPLEMENTED

Report problematic IPs to the abuse IP database

Installation

Install as composer package -- instructions to come.

Step 1. Enable Module

php bin/magento module:enable Cs_AbuseApi

Step 2. Magento setup:upgrade

php bin/magento setup:upgrade

Step 3. Clear cache and compile DI

php bin magento setup:di:compile && php bin/magento cache:flush

Step 4. Update Admin Configuration settings

Update configuration settings in admin: Stores > Configuration > Abuse Api Db

  • Enable module

  • Register For API Key and copy API Key into configuration field

https://www.abuseipdb.com/register

API Key

https://www.abuseipdb.com/register

Register for API Key.


Usage Example

<?phpuseCs\AbuseApi\Model\Service****Client;
//....class Testclass {
private$serviceClient;
//...publicfunction__construct(
ServiceClient$serviceClient
) {
$this->serviceClient = $serviceClient;
}
publicfunctiontestIpCheck($ip) {
return$this->serviceClient->checkIp($ip);
} publicfunctiontestIpsCheck($ips)
{
$collection = $this->serviceClient->checkIps([
'34.87.251.211',
'66.70.157.189',
'144.217.171.225',
'14.178.144.104',
'167.114.90.33',
'188.191.22.226',
'198.27.124.169'
],90);
return$collection;
}
}

Example Output

object(Cs\AbuseApi\Model\Client\CheckResponse)[416]
protected '_data' => array (size=13)
'ipAddress' => string '115.84.92.92' (length=12)
'isPublic' => boolean true
'ipVersion' => int 4
'isWhitelisted' => boolean false
'abuseConfidenceScore' => int 100
'countryCode' => string 'LA' (length=2)
'usageType' => null
'isp' => string 'Telecommunication Service' (length=25)
'domain' => string 'newworldtelecom.net' (length=19)
'hostnames' => array (size=0)
empty
'totalReports' => int 41
'numDistinctUsers' => int 12
'lastReportedAt' => string '2020-09-14T17:23:53+00:00' (length=25)

API Key

https://www.abuseipdb.com/register

account/api

Developer Notes:

Configuration Fields

Base URI => 'base_uri' API Key => 'api_key' Max Days => 'max_days'

Client and HEADERS

<?php$client = newGuzzleHttp\Client([
'base_uri' => 'https://api.abuseipdb.com/api/v2/'
]);
 'headers' => [
'Accept' => 'application/json',
'Key' => $YOUR_API_KEY
],

CHECK Endpoint

Check Parameters

fieldrequireddefaultminmax
ipAddressyes
maxAgeInDaysno301365
verboseno

$response = $client->request('GET', 'check', [ 'query' => [ 'ipAddress' => '118.25.6.39', 'maxAgeInDays' => '90', ],

Request Example

<?php$client = newGuzzleHttp\Client([
'base_uri' => 'https://api.abuseipdb.com/api/v2/'
]);
$response = $client->request('GET', 'check', [
'query' => [
'ipAddress' => '118.25.6.39',
'maxAgeInDays' => '90',
],
'headers' => [
'Accept' => 'application/json',
'Key' => $YOUR_API_KEY
],
]);
$output = $response->getBody();
// Store response as a PHP object.$ipDetails = json_decode($output, true);
?>

Response Example

{
"data": {
"ipAddress": "118.25.6.39",
"isPublic": true,
"ipVersion": 4,
"isWhitelisted": false,
"abuseConfidenceScore": 100,
"countryCode": "CN",
"countryName": "China",
"usageType": "Data Center/Web Hosting/Transit",
"isp": "Tencent Cloud Computing (Beijing) Co. Ltd",
"domain": "tencent.com",
"hostnames": [],
"totalReports": 1,
"numDistinctUsers": 1,
"lastReportedAt": "2018-12-20T20:55:14+00:00",
"reports": [
{
"reportedAt": "2018-12-20T20:55:14+00:00",
"comment": "Dec 20 20:55:14 srv206 sshd[13937]: Invalid user oracle from 118.25.6.39",
"categories": [
18,
22
],
"reporterId": 1,
"reporterCountryCode": "US",
"reporterCountryName": "United States"
}
]
}
}

Categories

IDTitleDescription
1DNS CompromiseAltering DNS records resulting in improper redirection.
2DNS PoisoningFalsifying domain server cache (cache poisoning).
3Fraud OrdersFraudulent orders.
4DDoS AttackParticipating in distributed denial-of-service (usually part of botnet).
5FTP Brute-Force
6Ping of DeathOversized IP packet.
7PhishingPhishing websites and/or email.
8Fraud VoIP
9Open ProxyOpen proxy, open relay, or Tor exit node.
10Web SpamComment/forum spam, HTTP referer spam, or other CMS spam.
11Email SpamSpam email content, infected attachments, and phishing emails. Note: Limit comments to only relevent information (instead of log dumps) and be sure to remove PII if you want to remain anonymous.
12Blog SpamCMS blog comment spam.
13VPN IPConjunctive category.
14Port ScanScanning for open ports and vulnerable services.
15Hacking
16SQL InjectionAttempts at SQL injection.
17SpoofingEmail sender spoofing.
18Brute-ForceCredential brute-force attacks on webpage logins and services like SSH, FTP, SIP, SMTP, RDP, etc. This category is seperate from DDoS attacks.
19Bad Web BotWebpage scraping (for email addresses, content, etc) and crawlers that do not honor robots.txt. Excessive requests and user agent spoofing can also be reported here.
20Exploited HostHost is likely infected with malware and being used for other attacks or to host malicious content. The host owner may not be aware of the compromise. This category is often used in combination with other attack categories.
21Web App AttackAttempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdmin and various other software plugins/solutions.
22SSHSecure Shell (SSH) abuse. Use this category in combination with more specific categories.
23IoT TargetedAbuse was targeted at an "Internet of Things" type device. Include information about what type of device was targeted in the comments.

"1 " => "" Altering DNS records resulting in improper redirection. ", "2 " => "" Falsifying domain server cache (cache poisoning). ", "3 " => "" Fraudulent orders. ", "4 " => "" Participating in distributed denial-of-service (usually part of botnet). ", "5 " => "" ", "6 " => "" Oversized IP packet. ", "7 " => "" Phishing websites and/or email. ", "8 " => "" ", "9 " => "" Open proxy, open relay, or Tor exit node. ", "10" => "Comment/forum spam, HTTP referer spam, or other CMS spam. ", "11" => "Spam email content, infected attachments, and phishing emails. Note: Limit comments to only relevant information (instead of log dumps) and be sure to remove PII if you want to remain anonymous. ", "12" => "CMS blog comment spam. ", "13" => "Conjunctive category. ", "14" => "Scanning for open ports and vulnerable services. ", "15" => "" ", "16" => "Attempts at SQL injection. ", "17" => "Email sender spoofing. ", "18" => "Credential brute-force attacks on webpage logins and services like SSH, FTP, SIP, SMTP, RDP, etc. This category is seperate from DDoS attacks. ", "19" => "Webpage scraping (for email addresses, content, etc) and crawlers that do not honor robots.txt. Excessive requests and user agent spoofing can also be reported here. ", "20" => "Host is likely infected with malware and being used for other attacks or to host malicious content. The host owner may not be aware of the compromise. This category is often used in combination with other attack categories. ", "21" => "Attempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdmin and various other software plugins/solutions. ", "22" => "Secure Shell (SSH) abuse. Use this category in combination with more specific categories. ", "23" => "Abuse was targeted at an "Internet of Things" type device. Include information about what type of device was targeted in the comments. ",

About

Magento2 Abuse IP DB Api Integration

Topics

Resources

Stars

5 stars

Watchers

1 watching

Forks

Releases

Sponsor this project

Packages

Used by

Contributors

Languages