التوثيق / مرجع الواجهة
سمعة عنوان IP
تُرجع مؤشرات التهديد فقط لعنوان IP: البروكسي وVPN وTor والروبوتات والمُرحِّلات والاستضافة وحالة القائمة السوداء.
نظرة عامة#
lookup/ip/threats هي الطريقة الخفيفة لسؤال "هل هذا العنوان خطِر؟". وبخلاف فحص عنوان IP فهي تتجاوز الجغرافيا والمنطقة الزمنية والعملة وتُرجع ip وكائن threats فقط. فتأتي الاستجابات صغيرة وسريعة، وهذا يناسب الفحص في المسار الحرج لتسجيل الدخول أو الدفع.
متى تستخدمها#
- فرز سريع بنجاح/رفض قبل إنشاء حساب أو بدء عملية دفع.
- قرارات تعتمد فقط على إشارات إخفاء الهوية والأتمتة.
- مسارات عالية الحجم لا تحتاج بيانات الموقع.
قراءة النتيجة#
threats.isProxyتدل على بنية إخفاء الهوية وthreats.proxyTypeتسمّي نوعها. كثير من المستخدمين الشرعيين يستخدمون VPN، فالأفضل طلب تحقق إضافي (رمز لمرة واحدة مثلًا) بدل الحظر المباشر.threats.isHostingتوحي بأن الزيارة من مركز بيانات لا من شخص. ومعthreats.isBotتكون سببًا وجيهًا للتحدي أو الرفض.threats.isTorتعني عقدة خروج في شبكة Tor، وthreats.isRelayتعني مُرحِّل خصوصية، وهو غالبًا حميد لكنه يخفي الموقع الحقيقي.threats.blacklistedتكون true عند تطابق العنوان مع قوائمك السوداء، وthreats.custom_rules_appliedتسرد القواعد المخصصة التي انطبقت.
سياسة عملية مقترحة: اسمح حين تكون كل القيم false، واطلب تحققًا إضافيًا حين تكون isProxy أو isRelay وحدها true، واحظر أو راجِع حين تقترن isTor أو isBot أو isHosting بإشارة خطر أخرى.
ملاحظات#
- تُحتسب طلبًا واحدًا. وضع الاختبار يُرجع بيانات وهمية مجانًا دون أحداث.
- مشمولة في كل الباقات.
- يمكن للقواعد المخصصة في مجموعة سمعة IP اختبار نوع البروكسي وكل مؤشر والدولة، وإضافة العنوان إلى قائمة سوداء أو بيضاء.
- يُطلَق حدث
suspicious_ipعند بلوغ الخطورة 50 من 100 ويصل إلى الويب هوك. - العنوان المفقود أو غير الصحيح يُرجع الخطأ 112 (
invalid_ip) مع HTTP 200.
الطلب#
https://gurdx.cretip.com/api/lookup/ip/threats
- صادِق بمعامل key أو بترويسة Authorization: Bearer.
- تُحتسب طلباً واحداً.
- متاحة في: تجربة مجانية القياسية المميّزة الدفع حسب الاستخدام
المعاملات#
| الاسم | النوع | الوصف |
|---|---|---|
ip
مطلوب
استعلام |
string |
The ip parameter is used to specify the IP address you want to retrieve it's threat intelligence information. Expected values: an IP address (IPv4 or IPv6) Sample value: 1.1.1.1
|
تقبل كل خدمة أيضاً format, lang, mode, userID, callback. راجع الخيارات.
أمثلة برمجية#
curl -G "https://gurdx.cretip.com/api/lookup/ip/threats" \
--data-urlencode "key=YOUR_API_KEY" \
--data-urlencode "ip=1.1.1.1"
<?php
$response = file_get_contents('https://gurdx.cretip.com/api/lookup/ip/threats?'.http_build_query(['key' => 'YOUR_API_KEY', 'ip' => '1.1.1.1']));
$result = json_decode($response, true);
if ($result['status'] === 'success') {
print_r($result['data']);
} else {
echo $result['code'].': '.$result['description'];
}
const params = new URLSearchParams({"key":"YOUR_API_KEY","ip":"1.1.1.1"});
const res = await fetch(`https://gurdx.cretip.com/api/lookup/ip/threats?${params}`);
const result = await res.json();
if (result.status === 'success') {
console.log(result.data);
} else {
console.error(result.code, result.description);
}
import requests
res = requests.get("https://gurdx.cretip.com/api/lookup/ip/threats", params={"key": "YOUR_API_KEY", "ip": "1.1.1.1"})
result = res.json()
if result["status"] == "success":
print(result["data"])
else:
print(result["code"], result["description"])
الاستجابة#
نجاح#
{
"status": "success",
"data": {
"ip": "12.12.12.12",
"threats": {
"isProxy": true,
"proxyType": "Socks",
"isTor": false,
"isBot": false,
"isRelay": false,
"isHosting": true,
"blacklisted": false
},
"custom_rules_applied": {
"total": 0,
"rules": []
}
},
"executionTime": 90
}خطأ#
تُسلَّم الأخطاء بحالة HTTP 200 — افحص دائماً حقل status.
{
"status": "error",
"code": 101,
"type": "invalid_key",
"description": "The API Key is missing or invalid."
}حقول الاستجابة#
| الاسم | النوع | الوصف |
|---|---|---|
data.ip |
string |
IP address you're looking up. |
data.threats.isProxy |
boolean |
Indicates if the IP address is a proxy service. |
data.threats.proxyType |
string |
Type of proxy used. |
data.threats.isTor |
boolean |
Indicates if accessed through Tor network. |
data.threats.isBot |
boolean |
Indicates if the user is a bot. |
data.threats.isRelay |
boolean |
Indicates if it's a Apple's Private Relay connection. |
data.threats.isHosting |
boolean |
Indicates if the IP address belong to a hosting provider. |
data.threats.blacklisted |
boolean |
Indicates if the IP address is blacklisted due to applying custom rules or were found in one of your blacklists. |
data.threats.custom_rules_applied.total |
integer |
The total number of custom rules applied to this request. |
data.threats.custom_rules_applied.rules.id |
string |
The rule ID as shown in the dashboard (e.g: CR104).
|
data.threats.custom_rules_applied.rules.title |
string |
The rule title you set when creating the rule. |
data.threats.custom_rules_applied.rules |
object |
The custom rules applied to this request, learn more. |
data.threats.custom_rules_applied |
object |
The custom rules applied to this request, learn more. |
data.threats |
object |
— |
data.status |
string |
Response status (success/error). |
data.executionTime |
integer |
Time taken to process the data (in milliseconds). |
data |
object |
— |
وجدت خطأ؟ أخبرنا عبر صفحة التواصل. تواصل معنا