Re: [SLUG] IP spoofing and tracking

From: Bpreece (bpreece1@tampabay.rr.com)
Date: Sat Feb 23 2002 - 01:23:47 EST


Well here is a few things one Road Runner Users get this alot.
Next he should run Zone Alarm if he is using Winders it is free and works
very well.
Next It will give you a ip that is trying to hit his system.

Now with that McAfee has a Utility that will indeed sniff out the location
of this person whom
is ping bombing him. Now then I can tell you if it is from another Road
Runner user, Road Runner
Will do absoultley nothing about this. They do not feel it is worth
bothering. They will then say that you
should be running a firewall and what do you want them to do about it?!

If it turns out to be from another domain and isp though then he should
contact that isp and report the person and send them
a copy of the log file from the Firewall.

That is about all you can do.

Unless you get him to switch to LINUX 8-)
Then you can tell him to update all the security patches and updates. Set up
a BSD firewall!
You know the rest of the story so preach the Open Source Gosple to him!

-----Original Message-----
From: Norbert Cartagena <niccademous@yahoo.com>
To: slug@nks.net <slug@nks.net>
Date: Saturday, February 23, 2002 12:43 AM
Subject: [SLUG] IP spoofing and tracking

>Ok, security question here for both Linux and Windows:
>
>I have a friend (Using Win2k a his main box, that poor lost soul) who
>has as of late been getting ping-bombed. He lives in an appartment
>complex that has their own internal LAN for the entire complex. He was
>able to find out the IP from where the pings were apparently comming
>from. However, when he tracked it down, he found out that it wasn't the
>person with that IP doing that - someone was spoofing their IP to this
>other person's. He was able to determine that the pings were comming
>from within their network, but hasn't been able toget any more info than
>that. I was wondering if there was a tool - under either Windows or
>Linux - that would be able to track the IP to the true source, a way of
>somehow un-spoofing the address?
>
>I know this must seem vague, but I didn't get too many details when I
>was talking to this guy - I was kinda in the middle of something that
>took a bit more of my attention at that particular moment - so my
>appologies if it seems almost like random babble.
>
>Gnorb
>



This archive was generated by hypermail 2.1.3 : Fri Aug 01 2014 - 16:32:01 EDT