DescriptionThe script is almost entirely passive, but does do reverse lookups on observed IPs.
It would be possible to generate traffic from a "canary" ip if the block was delegated to your name server. If a PTR request is received for that IP then someone is taking an interest in your traffic.
So should introduce a config option to allow the script to be limited to truly passive analysis
Activity
2015-11-27 12:49:25
Where is has a non-zero value, only truly passive checks will be run. At the moment that simply means the PTR's on associated IP's won't happen, but obviously in the future there may be more to it than that.
2015-11-27 12:49:48
Webhook User-Agent
View Commit
2015-11-27 12:49:49
2015-11-27 12:49:58
2015-11-27 12:49:58
2015-11-27 12:50:04
2015-11-27 13:12:03
2015-11-27 13:12:03
2015-11-27 13:12:03
2015-11-27 13:12:20
2015-11-27 13:12:20
2015-11-27 13:12:26