|
EJ
|
 |
« Reply #15 on: March 21, 2004, 09:55:54 AM » |
|
Can this whois thing be used to trace down someone who sent me a virus? I put the IP# that was in the email and some cable company out of calgary came up, would that mean my little virus speader was from the calgary area and the cable company is thier ISP?
|
|
|
|
|
Logged
|
I love the new LPF theme
|
|
|
Tristan
Resident Alien
Administrator
Berserker Poster
   
Offline
Posts: 9237
nihil sunt omnia
|
 |
« Reply #16 on: March 21, 2004, 09:59:36 AM » |
|
Hi EJ,
Yes, it would be that is their ISP. You can contact the ISP and provide the IP number to them, letting them know that you received a virus email from that individual. Paste the full header in the email you send to the ISP and highlight the IP of the individual. Also, include the whois trace you did that showed the IP traced to them as the ISP.
I hope this helps.
|
|
|
|
|
Logged
|
|
|
|
|
EJ
|
 |
« Reply #17 on: March 21, 2004, 10:04:41 AM » |
|
Thanks Danielle, Another quik question? I just did the email address also, I had forwarded this email to abuse@hotmail.com and THEY said its was a forged email BUT according to whois it IS a valid email, Did hotmail tell a fib? or am I missing something.
|
|
|
|
|
Logged
|
I love the new LPF theme
|
|
|
Tristan
Resident Alien
Administrator
Berserker Poster
   
Offline
Posts: 9237
nihil sunt omnia
|
 |
« Reply #18 on: March 21, 2004, 10:06:09 AM » |
|
Hi EJ,
Could you post the full header so that we can all look at it? This way I can see who the original IP sender happened to be.
Thanks
|
|
|
|
|
Logged
|
|
|
|
|
EJ
|
 |
« Reply #19 on: March 21, 2004, 10:15:39 AM » |
|
Return-path: < jewels3d21@hotmail.com> Envelope-to: webmaiden@steelsheen.comDelivery-date: Fri, 19 Mar 2004 21:21:18 -0800 Received: from [68.150.64.57] (helo=steelsheen.com) by abell.lunarpages.com with esmtp (Exim 4.24) id 1B4Yv6-0007ex-Qm for webmaiden@steelsheen.com; Fri, 19 Mar 2004 21:21:16 -0800 From: jewels3d21@hotmail.comTo: webmaiden@steelsheen.comSubject: Re: unknown Date: Fri, 19 Mar 2004 22:20:18 -0700 MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="----=_NextPart_000_0000_000021A7.00003E43" X-Priority: 3 X-MSMail-Priority: Normal Message-Id: < E1B4Yv6-0007ex-Qm@abell.lunarpages.com> here it is
|
|
|
|
|
Logged
|
I love the new LPF theme
|
|
|
|
EJ
|
 |
« Reply #20 on: March 21, 2004, 10:18:05 AM » |
|
what does it all mean...... lol
|
|
|
|
|
Logged
|
I love the new LPF theme
|
|
|
Tristan
Resident Alien
Administrator
Berserker Poster
   
Offline
Posts: 9237
nihil sunt omnia
|
 |
« Reply #21 on: March 21, 2004, 10:22:18 AM » |
|
Hi EJ, The email jewels3d21@hotmail.com is a forged email. People take other email/domain names of existing domains/addresses and spoof them. Thus, this would not be the originating email address. You aren't required when sending email to put a valid from address in that field at all, and this should never be assumed to be the originating email account. The original, first IP noted in the first Received from: field, however, can't be forged. It is the following (if you included the full header above that is): Received: from [68.150.64.57] That is the one that you would need to verify the ISP and could send a note with the full email and header to that ISP to complain. I hope this is useful.
|
|
|
|
|
Logged
|
|
|
|
|
Pete
|
 |
« Reply #22 on: March 21, 2004, 10:23:21 AM » |
|
hmm. interestingly.. A lot of the virus ( netsky) I've been getting recently have come from ( or seem to ) a hosting company in Calgary. I also sent them an email asking if they could speak to whomever it was sending them out. To let them know they were doing it if they wernt aware and sort out their machines ( I was quite nice about it ) I havent heard a reply back yet 
|
|
|
|
|
Logged
|
|
|
|
|
Pete
|
 |
« Reply #23 on: March 21, 2004, 10:25:10 AM » |
|
AND LO. Its the same company 
|
|
|
|
|
Logged
|
|
|
|
|
EJ
|
 |
« Reply #24 on: March 21, 2004, 10:29:39 AM » |
|
Yes I included the whole thing, Danielle...Thanks your a peach!
OK! thanks Pete!
I should send it on to them. So email CAN be forged but the IP CAN'T? thats good to know, and its always the first IP listed?
|
|
|
|
|
Logged
|
I love the new LPF theme
|
|
|
Tristan
Resident Alien
Administrator
Berserker Poster
   
Offline
Posts: 9237
nihil sunt omnia
|
 |
« Reply #25 on: March 21, 2004, 10:33:50 AM » |
|
Hi EJ, Yes, it is always the very first IP listed in the very first Received: from field. That is how the header is read. I just look for the first one, and tell people that IP. It is a good way to check to ensure your own IP isn't infected with a virus and sending you emails (people sometimes get them from their own domain as a bounce). And thanks for the thanks. 
|
|
|
|
|
Logged
|
|
|
|
|
BigSee
|
 |
« Reply #26 on: April 30, 2004, 06:57:43 AM » |
|
|
|
|
|
|
Logged
|
|
|
|
|
Mithrandread
|
 |
« Reply #27 on: June 01, 2004, 09:32:44 PM » |
|
I have an odd question. I signed up with Lunarpages in January. I know that I made the necesary changes for things to point to Lunarpages, as I read the how to on whois in the how to section. Yet, a few minutes ago when I did a whois search on my domain, dreadhead7.com, the nameservers don't point to Lunarpages. Am I not seeing things right? I am sure that I own the domain name, as I purchased it two years ago. Will someone do a check to see if I'm not mistaken? How do I know if my site is truely being hosted by Lunarpages? Sorry, but I'm starting to freak out here! Thanks in advance, Dread
|
|
|
|
|
Logged
|
|
|
|
|
leighsww
|
 |
« Reply #28 on: June 01, 2004, 10:20:11 PM » |
|
Yet, a few minutes ago when I did a whois search on my domain, dreadhead7.com, the nameservers don't point to Lunarpages. Am I not seeing things right? You look just fine to me. The servers you are showing are Lunarpages' DNS servers. Latter signups will point to NS1.LUNARPAGES.COM servers, but the "DYNAMICNAME" ones are correct, as well: Domain Name: DREADHEAD7.COM Registrar: MELBOURNE IT, LTD. D/B/A INTERNET NAMES WORLDWIDE Whois Server: whois.melbourneit.com Referral URL: http://www.melbourneit.com Name Server: NS2.DYNAMICNAME.COM Name Server: NS1.DYNAMICNAME.COM Status: ACTIVE Updated Date: 05-jan-2004 Creation Date: 17-oct-2002 Expiration Date: 17-oct-2004
|
|
|
|
|
Logged
|
|
|
|
|
Mithrandread
|
 |
« Reply #29 on: June 01, 2004, 10:50:37 PM » |
|
Whew, I'm relieved! I saw all that information about my former host, and nothing that referred directly to Lunarpages, and it scared me...I didn't even notice the update date...thanks a bunch!
|
|
|
|
|
Logged
|
|
|
|
|