Re: [SLUG] Detective work on hosts

From: steve szmidt (steve@szmidt.org)
Date: Tue Mar 28 2006 - 11:32:06 EST


On Tuesday 28 March 2006 10:43, Paul M Foster wrote:
> Does anyone know a way (using host, traceroute or whatever) to track
> down where a site or hosting company is hosted? For example, if a
> hosting company has a certain IP, can you find out where that IP came
> from, who assigned it, etc.? Or can you find out who has which IP
> blocks? (Hope that makes sense.)

If you have an IP you can indeed run whois on it. You can also go to arin,
ripe and iana and find out from the top authorities who is responsible for
that IP. What I usually do if it is an ISP I've never heard from, I lookup
their dns too. Through that I find their ISP.

Often times you'll find spammers have their own ISP. So then I make sure that
a real ISP is aware of the problem being caused downstream, since complaining
to the spammers own ISP is not going to help, except make sure you get even
more spam.

If the spam ISP get's enough complaints on it the real ISP may shut them down.

Too many smaller ISP's don't want to kill a good paying client. So you'll need
the pressure on them being closed down entirely, which you get if the real
ISP knows what is going on. Sometimes I end up copying several layers if the
proximity between the ISP's are too close and might be owned by the same
people. This is not the place to be "nice" either. Spamming is hard business.

-- 

Steve Szmidt

"For evil to triumph all that is needed is for good men to do nothing. Edmund Burke ----------------------------------------------------------------------- This list is provided as an unmoderated internet service by Networked Knowledge Systems (NKS). Views and opinions expressed in messages posted are those of the author and do not necessarily reflect the official policy or position of NKS or any of its employees.



This archive was generated by hypermail 2.1.3 : Fri Aug 01 2014 - 20:06:32 EDT