> Ok but these proxies almost certainly reverse-tunnel. How do you prove a customer is hosting one?
Why do you think that? These are proxies, so they're making huge numbers of outbound connections to websites on behalf of the people operating them. They are the "exit nodes" in this setup.
You could probably just count the number of unique destination IPs they connect to each day. If the average residential user connects to 5,000, an infected machine is probably connecting to 50,000+.
But the simplest approach is to buy access to these illicit proxy services and use them to make requests to web servers you control. If you see your own unique request arrive from a residential IP, you've proven that connection is being used as a proxy.
> Ok but these proxies almost certainly reverse-tunnel. How do you prove a customer is hosting one?
Why do you think that? These are proxies, so they're making huge numbers of outbound connections to websites on behalf of the people operating them. They are the "exit nodes" in this setup.
You could probably just count the number of unique destination IPs they connect to each day. If the average residential user connects to 5,000, an infected machine is probably connecting to 50,000+.
But the simplest approach is to buy access to these illicit proxy services and use them to make requests to web servers you control. If you see your own unique request arrive from a residential IP, you've proven that connection is being used as a proxy.