AVForums

Our philosophy in our forums, reviews, podcasts and feature videos is to promote audio and visual excellence by gathering and sharing the best information and resources available.

Help

To begin please visit our help section »

Not a Member Yet?

It only takes a minute to start enjoying the benefits of AVForums membership, and it's free!

Member Log in

Can you trace an IP address?

Post Reply
Old 04-06-2006, 8:23 PM   #1
Conspicuous Member
 
PJTX100's Avatar
Join Date: Dec 2004
Experience Points:
16,232, Level: 30
Points: 16,232, Level: 30 Points: 16,232, Level: 30 Points: 16,232, Level: 30
Activity: 1.1%
Activity: 1.1% Activity: 1.1% Activity: 1.1%
Thanks: Gave 402, Got 566
Posts: 8,102
Can you trace an IP address?

For all you computer geniuses out there...

It looks as if someone has been running some sort of hacking script today on a server I help to look after because it's tried 15000 times unsuccessfully to find a valid user account and password. I have an IP address of the source but nothing else.

Is there much I can find out about the perpetrator from an IP address?
  Quote
Old 04-06-2006, 8:27 PM   #2
Senior Member
 
Reign-Mack's Avatar
Join Date: Dec 2005
Location: Central London
Experience Points:
11,029, Level: 25
Points: 11,029, Level: 25 Points: 11,029, Level: 25 Points: 11,029, Level: 25
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Blog Entries: 1
Thanks: Gave 1,264, Got 219
Posts: 2,199
http://www.dnsstuff.com/
  Quote
Old 04-06-2006, 8:28 PM   #3
Ex Member
Join Date: Nov 2004
Experience Points:
29,695, Level: 42
Points: 29,695, Level: 42 Points: 29,695, Level: 42 Points: 29,695, Level: 42
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Thanks: Gave 69, Got 316
Posts: 9,729
You need a "Whois" lookup. The one I use is the one on the Demon Tools Pages but there are lots of others.

The IP address could lead to you a block held by a major ISP, in which case you would have to lodge a complaint with the ISP, giving details of the transgressions and times that they occurred.
  Quote
Old 04-06-2006, 8:29 PM   #4
retired member
Join Date: Oct 2004
Experience Points:
21,535, Level: 35
Points: 21,535, Level: 35 Points: 21,535, Level: 35 Points: 21,535, Level: 35
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Thanks: Gave 4, Got 217
Posts: 3,355
I use Visual Route personally - but there's several programs out there.
  Quote
Old 04-06-2006, 8:31 PM   #5
Prominent Member
 
Digger's Avatar
Join Date: Dec 2003
Location: World Wide Supermarket
Experience Points:
8,197, Level: 21
Points: 8,197, Level: 21 Points: 8,197, Level: 21 Points: 8,197, Level: 21
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Thanks: Gave 232, Got 200
Posts: 3,926
If there is not one, consider getting a hardware firewall to trap and log ports targeted. Contact the isp and get them involved assuming its a business thats being targeted...probably nothing they can do though.
  Quote
Old 04-06-2006, 8:34 PM   #6
Conspicuous Member
 
PJTX100's Avatar
Join Date: Dec 2004
Experience Points:
16,232, Level: 30
Points: 16,232, Level: 30 Points: 16,232, Level: 30 Points: 16,232, Level: 30
Activity: 1.1%
Activity: 1.1% Activity: 1.1% Activity: 1.1%
Thanks: Gave 402, Got 566
Posts: 8,102
Thanks everyone. Looks like it originated in the US. My money was on eastern block.
  Quote
Old 04-06-2006, 9:19 PM   #7
Senior Member
 
Dom996's Avatar
Join Date: Jun 2005
Experience Points:
4,125, Level: 15
Points: 4,125, Level: 15 Points: 4,125, Level: 15 Points: 4,125, Level: 15
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Thanks: Gave 24, Got 37
Posts: 1,048
Very difficult to trace on two (and more) levels:

One: ISPs need to be competititive so don't really want to annoy customers. Oh of course that is unless they are caning bandwidth!!

Two: Many IPs are still dynamic, ie. change on a regular basis, and let's not go into proxies.....
  Quote
Old 04-06-2006, 10:05 PM   #8
Distinguished Member
 
Knyght_byte's Avatar
Join Date: Nov 2004
Location: Harrow, NW London
Experience Points:
22,867, Level: 36
Points: 22,867, Level: 36 Points: 22,867, Level: 36 Points: 22,867, Level: 36
Activity: 3.8%
Activity: 3.8% Activity: 3.8% Activity: 3.8%
Thanks: Gave 96, Got 655
Posts: 10,905
used to use a ping tool years ago, was amazingly effecient at getting thru things.....sadly it was only a 15 day demo.......was quite effective as it basically ignored firewalls etc and could locate the area easily......it couldnt give you any more information tho......that was the downside.....cant remember what it was called, not sure how it would stand up to more recent network/ISP setups tho, this was about 3 years ago....
  Quote
Old 05-06-2006, 5:56 AM   #9
Eminent Member
 
Ian J's Avatar
Join Date: Aug 2001
Location: Midlands
Experience Points:
71,654, Level: 65
Points: 71,654, Level: 65 Points: 71,654, Level: 65 Points: 71,654, Level: 65
Activity: 0.8%
Activity: 0.8% Activity: 0.8% Activity: 0.8%
Blog Entries: 3
Thanks: Gave 3,114, Got 4,720
Posts: 23,949
Quote:
Originally Posted by Dom996
let's not go into proxies.....

Especially on AV Forums eh Dom
  Quote
Old 05-06-2006, 9:52 AM   #10
Ex Member
 
Ethics Gradient's Avatar
Join Date: Jul 2003
Location: aka Billy Science - Suni ojna Tas
Experience Points:
15,477, Level: 30
Points: 15,477, Level: 30 Points: 15,477, Level: 30 Points: 15,477, Level: 30
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Thanks: Gave 48, Got 445
Posts: 3,681
Quote:
Originally Posted by PJTX100
Thanks everyone. Looks like it originated in the US. My money was on eastern block.
there is no guarantee that it isn't.

You are only seeing the traces between the box he is trying to connect to you from to you ... ie the packet routing between machine X on the internet and your box.
Unless the guy / girl is a complete divey, it would be unlikely that the machine in question is his.( although don't rule it out as there are plenty of fools out there )

You will not however know what connections he has made to get to the box that is being used to 'attack' your machine.

He could be absolutley anywhere - as he may have a legit or hacked shell account on one of many boxes.
Most people would log in through an inet cafe into a shell account on a server - then run a script from there ..... with no trail back to themselves.
The only thing you can hope for is that the machine / account that is being used is closed down.
Contanct the domain administrator for what ever machine is causing you trouble - be it an ISP / Business etc and give them the details and hope they look into it for you.
You could also block that address on your routers to just ignore the connection, set up .allow / .deny etc files for what ever services are available on your machine ... ie allow or deny specific IP ranges / domains etc from connecting to your machine.
  Quote
Old 05-06-2006, 10:16 AM   #11
Conspicuous Member
 
PJTX100's Avatar
Join Date: Dec 2004
Experience Points:
16,232, Level: 30
Points: 16,232, Level: 30 Points: 16,232, Level: 30 Points: 16,232, Level: 30
Activity: 1.1%
Activity: 1.1% Activity: 1.1% Activity: 1.1%
Thanks: Gave 402, Got 566
Posts: 8,102
Quote:
Originally Posted by Ethics Gradient
You could also block that address on your routers to just ignore the connection, set up .allow / .deny etc files for what ever services are available on your machine ... ie allow or deny specific IP ranges / domains etc from connecting to your machine.
Thanks, that sounds like a good idea, I'll look into it.
  Quote
Old 05-06-2006, 10:19 AM   #12
Conspicuous Member
 
PJTX100's Avatar
Join Date: Dec 2004
Experience Points:
16,232, Level: 30
Points: 16,232, Level: 30 Points: 16,232, Level: 30 Points: 16,232, Level: 30
Activity: 1.1%
Activity: 1.1% Activity: 1.1% Activity: 1.1%
Thanks: Gave 402, Got 566
Posts: 8,102
As a general question about this sort of attack, does this scale of attack happen all the time to servers connected to the internet?

I'm just trying to establish whether this is "par for the course" or something more systematic.
  Quote
Old 05-06-2006, 10:54 AM   #13
Ex Member
 
Ethics Gradient's Avatar
Join Date: Jul 2003
Location: aka Billy Science - Suni ojna Tas
Experience Points:
15,477, Level: 30
Points: 15,477, Level: 30 Points: 15,477, Level: 30 Points: 15,477, Level: 30
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Thanks: Gave 48, Got 445
Posts: 3,681
Quote:
Originally Posted by PJTX100
As a general question about this sort of attack, does this scale of attack happen all the time to servers connected to the internet?

I'm just trying to establish whether this is "par for the course" or something more systematic.
yes - people uses scripts on vast ranges of IP's looking for machines that are directly connected / have a redirect to them ... then see if they get a response to validate the operating system ... then start port scanning and log the results.
Then when they find ports that respond with a prompt / login - they try to either brute force ( dictionary type crack ) or look for things like a mail server running an older version with a known bug and try to break it dropping them into root for example.

--- then there are the focused attacks - ex employees, friends, pressure groups, people with grudges etc that target directly. These are where you would see DoS attacks etc.
  Quote
Old 05-06-2006, 1:44 PM   #14
Veteran Member
 
Chris Muriel's Avatar
Join Date: Jun 2002
Location: Manchester
Experience Points:
15,693, Level: 30
Points: 15,693, Level: 30 Points: 15,693, Level: 30 Points: 15,693, Level: 30
Activity: 13.6%
Activity: 13.6% Activity: 13.6% Activity: 13.6%
Thanks: Gave 510, Got 629
Posts: 6,244
Indeed. If you have a router/firewall have a look at the logs and be afraid!
(Although many of the events will actually be quite legit and harmless).

Chris Muriel, Manchester
  Quote
Old 05-06-2006, 9:20 PM   #15
Senior Member
 
Dom996's Avatar
Join Date: Jun 2005
Experience Points:
4,125, Level: 15
Points: 4,125, Level: 15 Points: 4,125, Level: 15 Points: 4,125, Level: 15
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Thanks: Gave 24, Got 37
Posts: 1,048
Quote:
Originally Posted by Ian J
Especially on AV Forums eh Dom
Ah, Ian it will surprise you to know that I have been moderating another forum, hence why I have been quiet on here for a while. It is hard work and I appreciate what you guys do.
  Quote
Post Reply



Thread information and display options
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off