Forum Moderators: buckworks

Message Too Old, No Replies

credit card fraud prevention based on ip ranges?

how do i exclude certain countries?

         

muesli

2:48 pm on Apr 18, 2003 (gmt 0)

10+ Year Member



(sorry if this question has been discussed before, couldn't find explicit answers with site search)

i'm selling intangible goods (downloads) in UK, DE, AT and CH and my chargebacks on worldpay are on the rise. i want to limit them towards an acceptable level.

for the UK i'm using worldpay and they offer (among other measures) IP-range-blocking mechanisms. as i'm exclusivly targeting UK users with my downloads i want to block all non-UK IP-addresses, but i don't exactly know how. (i allready do deffered processing/worldalert but that's not sufficient.)

an idea was to
1) exclude all non ripe ip-ranges (i found [iana.org...]
2) exclude all non UK-ranges (i found only [ripe.net...] not sure if that covers all ripe-ranges or not)

any advice?

muesli

9:24 pm on Apr 26, 2003 (gmt 0)

10+ Year Member



anybody?
(sorry for bumping but isn't this a question more of us are asking themselves?)

DaveAtIFG

10:07 pm on Apr 26, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Maxmind [maxmind.com] offers an open source and a premium service that is occasionally recommended here.

muesli

3:04 pm on May 14, 2003 (gmt 0)

10+ Year Member



i've found a free database: [ip-to-country.com...]

sullen

3:52 pm on May 14, 2003 (gmt 0)

10+ Year Member



Just a thought, Muesli, but are you sure that blocking all foreign IPs is a good idea?

Take me, for example. I often buy UK software online but as I am in Spain, my IP address will show as Spain.

Could you not:

a) use some sort of combination of Computer region settings and IP address.
b) block all countries from which you have had fraudulent transactions in the past (rather than all other countries)
c) use the combination of IP address and browser (I've had a few problems with fraudulent transactions and found that 80% of them were coming from 1 perticular browser/OS combination. Probably the same guy using different dial-ups. We blocked all the IP ranges for the dial-ups he was using).

Like I say, just a thought.