|
![]() |
|
Chiefs Baby
Join Date: Jan 2004
Location: Henderson, NV
Casino cash: $10000632
|
Tracking an IP to physical address
Ok
I am using IP Tracer to link an IP address to an area where port scans on my router are coming from. My router emails me a log every time it fills up with 200 deny's of access that are logged. I have 8 full logs in the last 16 hours and 1 IP address in particular keeps coming up 95% of the time. 98.64.112.152 It is coming from somwhere in MIAMI I don't know about the rest of you but I average about 1 log a day to a day and a half on a pretty regular basis so YES this raised an eyebrow. ![]() Could it be an infected computer that someone is launching thier attack from? Maybe. Has anyone ever looked into anything like this? Yea I know I'm just being paranoid but better to be paranoid than relaxed about it IMO. BTW another IP address that is there a lot in the last 10 hours is coming from BOSTON.... DAMN YOU CADMONKEY or AMNORIX. I really don't have anything on my PC you guys could actually want. ![]() ![]() Problem is I don't know what I woluld do if I had an address and phone #. Anyone else even give a flying rats ass if someone is running port scans at this rate on your router? http://www.ip-adress.com/ip_tracer/98.64.112.152 |
Posts: 5,638
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#2 |
MVP
Join Date: May 2005
Location: a
Casino cash: $10004900
|
The only thing you can do is contact the ISP that owns the IP address and tell them that such-and-such IP is running a scanner. Do not expect them to bother with it right away and do not be surprised if they don't do anything at all. Telling an ISP admin that they have IPs scanning on the Internet it similar to telling a police officer that someone is jaywalking, it's just not that big of a deal and it's happening constantly anyway so it's hardly worth the effort to look into.
|
Posts: 5,502
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#3 |
Has a particular set of skills
Join Date: Dec 2003
Location: On the water
Casino cash: $-791038
![]() |
There are literally millions of bots running scripts out there trying to find holes in pc's. No biggie as long as you are set up right. Get yourself a firewall that doesn't return pings and they don't even know you exsist on the internet superhighway.
open up a command line and type in: netstat -a That'll show you all active connections type in nbtstat /? that'll show you all the different options to get the host name but since you don't have rights on the ISP's domain you won't get good results but your ISP will know who it is. Free DNS stuff here: http://www.dnsstuff.com/
__________________
Mahomes is not a game manager. Release the Kraken. |
Posts: 81,343
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#4 | |
Chiefs Baby
Join Date: Jan 2004
Location: Henderson, NV
Casino cash: $10000632
|
Quote:
|
|
Posts: 5,638
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#5 |
Someone pass the antifreeze
Join Date: Oct 2005
Location: Miami (North Cuba)
Casino cash: $-2212181
|
My bad.
|
Posts: 15,944
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#6 |
'Tis my eye!
Join Date: Aug 2000
Location: Chiefsplanet
Casino cash: $8099900
|
There's no way to trace an IP address to a physical address, whether you mean geographically or in terms of physical network address. There's invariably devices between you that obscure the physical address of the attacker.
Furthermore, it's possible those IP addresses are spoofed. |
Posts: 104,421
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#7 |
Ain't no relax!
Join Date: Sep 2005
Casino cash: $-1441081
|
Don't worry about it. Chances are, the owner of the PC has no clue anyway.
__________________
![]() |
Posts: 48,873
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#8 |
'Tis my eye!
Join Date: Aug 2000
Location: Chiefsplanet
Casino cash: $8099900
|
|
Posts: 104,421
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#9 |
Supporter
Join Date: Mar 2003
Casino cash: $697626
|
If this is really a concern then invest in a firewall that you can globally deny pings but have filters that allow ping from specified IP's.
|
Posts: 17,258
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#10 | |
Chiefs Baby
Join Date: Jan 2004
Location: Henderson, NV
Casino cash: $10000632
|
Quote:
![]() I have logs that show the same addresses hitting a variety of ports but usually they hit a few and move on. I have never gotten this many logs that show ONE IP address that is hitting me nonstop. Maybe it is someone I pissed off playing TFC online? |
|
Posts: 5,638
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#11 | |
Chiefs Baby
Join Date: Jan 2004
Location: Henderson, NV
Casino cash: $10000632
|
Quote:
I've had to open ports on my router for STEAM online gaming. Will turning off global pings keep that from working right? |
|
Posts: 5,638
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#12 |
That's just f***in' stupid
Join Date: Aug 2000
Location: suburbia
Casino cash: $3687107
|
Pings use ICMP. Steam uses UDP and TCP. Steam should not require ICMP.
__________________
"Gentlemen, you can't fight in here, this is the war room!" |
Posts: 12,355
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#13 |
Chiefs Baby
Join Date: Jan 2004
Location: Henderson, NV
Casino cash: $10000632
|
|
Posts: 5,638
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#14 |
Starter
Join Date: Aug 2003
Location: i travel
Casino cash: $-191667
|
I know of an utility back in the early 00's that did what you described but am unable to find the name, but I was able to find http://www.geoiptool.com/ with a quick google search.
|
Posts: 194
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#15 | |
MVP
Join Date: Sep 2004
Location: San Diego, CA
Casino cash: $-1436658
|
Quote:
|
|
Posts: 5,186
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() ![]() |
|
|