Networking Forums

Networking Forums > Computer Networking > Linux Networking > how to find GoToMyPC's network

Reply
Thread Tools Display Modes

how to find GoToMyPC's network

 
 
ToddAndMargo@gbis.com
Guest
Posts: n/a

 
      09-21-2006, 02:45 AM
Hi All,

I am trying to stop unauthorized traffic to and from GoToMyPC (and
a list
of others). How to I figure out GoToMyPC's network for my iptables
"-d xxx.xxx.xxx.0/24" entry? (...0/24 may not always be the case,
depending
on subnet mask.)

I can get a particuar IP with "hostgotomypc.com" (66.151.158.183)
but
that only gives me one address. I what to block their entire domain,
including
poll.gotomypc.com (66.151.158.177). Somehow I think that
"-d 66.151.158.0/24" would be overkill and may actually block some
legitimate traffic.

Is there some network command that will tell me this? (Then I can
grep, sed, and awk my heart out!)

Many thanks,
-T

 
Reply With Quote
 
 
 
 
Bill Marcum
Guest
Posts: n/a

 
      09-21-2006, 03:40 PM
["Followup-To:" header set to comp.os.linux.networking.]
On 20 Sep 2006 19:45:15 -0700, (E-Mail Removed)
<(E-Mail Removed)> wrote:
> Hi All,
>
> I am trying to stop unauthorized traffic to and from GoToMyPC (and
> a list
> of others). How to I figure out GoToMyPC's network for my iptables
> "-d xxx.xxx.xxx.0/24" entry? (...0/24 may not always be the case,
> depending
> on subnet mask.)
>
> I can get a particuar IP with "hostgotomypc.com" (66.151.158.183)
> but
> that only gives me one address. I what to block their entire domain,
> including
> poll.gotomypc.com (66.151.158.177). Somehow I think that
> "-d 66.151.158.0/24" would be overkill and may actually block some
> legitimate traffic.
>
> Is there some network command that will tell me this? (Then I can
> grep, sed, and awk my heart out!)
>

Try whois on the ip address.


--
When someone says "I want a programming language in which I need only
say what I wish done," give him a lollipop.
 
Reply With Quote
 
ficken
Guest
Posts: n/a

 
      09-21-2006, 06:34 PM
You could use a proxy server to block this traffic - if there is one
currently online this would probably be the most efficient way. Squid
should work.

If you do not have the time/resources/energy to implement a solution
such as this (and it can be a very cumbersome task) then a sweeping
block may be your best bet.

Bill Marcum wrote:
> ["Followup-To:" header set to comp.os.linux.networking.]
> On 20 Sep 2006 19:45:15 -0700, (E-Mail Removed)
> <(E-Mail Removed)> wrote:
>> Hi All,
>>
>> I am trying to stop unauthorized traffic to and from GoToMyPC (and
>> a list
>> of others). How to I figure out GoToMyPC's network for my iptables
>> "-d xxx.xxx.xxx.0/24" entry? (...0/24 may not always be the case,
>> depending
>> on subnet mask.)
>>
>> I can get a particuar IP with "hostgotomypc.com" (66.151.158.183)
>> but
>> that only gives me one address. I what to block their entire domain,
>> including
>> poll.gotomypc.com (66.151.158.177). Somehow I think that
>> "-d 66.151.158.0/24" would be overkill and may actually block some
>> legitimate traffic.
>>
>> Is there some network command that will tell me this? (Then I can
>> grep, sed, and awk my heart out!)
>>

> Try whois on the ip address.
>
>

 
Reply With Quote
 
Moe Trin
Guest
Posts: n/a

 
      09-21-2006, 07:52 PM
On 20 Sep 2006, in the Usenet newsgroup comp.os.linux.networking, in article
<(E-Mail Removed) .com>, (E-Mail Removed)
wrote:

> I can get a particuar IP with "hostgotomypc.com" (66.151.158.183)
>but that only gives me one address. I what to block their entire domain,
>including poll.gotomypc.com (66.151.158.177).


Well, a 'whois' on the domain returns

Registrant:
Expertcity, Inc.
5385 Hollister Ave
Suite 111
Santa Barbara, CA 93111
US
Domain Name: GOTOMYPC.COM

and then asking about the address at ARIN, I find

[whois.arin.net]
Internap Network Services PNAP-06-2001 (NET-66-150-0-0-1)
66.150.0.0 - 66.151.255.255
Expertcity PNAP-SJE-EXPERT-RM-02 (NET-66-151-158-0-1)
66.151.158.0 - 66.151.158.255

and asking about 'NET-66-151-158-0-1' does indeed return the same
postal address information.

>Somehow I think that "-d 66.151.158.0/24" would be overkill and may
>actually block some legitimate traffic.


I can't say - we're blocking the /15, and none of my users are complaining
about missing anything - YMMV. Looking at
http://www.TQMcube.com/rblcheck.htm, 66.151.158.0/24 doesn't appear to be
listed directly, but if you google for specific address ranges in the
newsgroups "news.admin.net-abuse.*" you'll probably turn up some hints
about who "owns" an address range, and any problems others are reporting.

>Is there some network command that will tell me this? (Then I can
>grep, sed, and awk my heart out!)


Most distributions come with a 'whois' tool - there are quite a number of
them. Try 'locate whois' and see if one is installed on your system.

Some RFCs to look at:

1834 Whois and Network Information Lookup Service, Whois++. J.
Gargano, K. Weiss. August 1995. (Format: TXT=14429 bytes) (Status:
INFORMATIONAL)

2167 Referral Whois (RWhois) Protocol V1.5. S. Williamson, M. Kosters,
D. Blacka, J. Singh, K. Zeilstra. June 1997. (Format: TXT=136355
bytes) (Obsoletes RFC1714) (Status: INFORMATIONAL)

3912 WHOIS Protocol Specification. L. Daigle. September 2004. (Format:
TXT=7770 bytes) (Obsoletes RFC0954, RFC0812) (Status: DRAFT STANDARD)

The major problem is knowing who to ask. For IP addresses, you would start
with the five Regional Internet Registry (AFRINIC, APNIC, ARIN, LACNIC, and
RIPE). See http://www.iana.org/assignments/ipv4-address-space to get a clue
as to which to ask. They _might_ refer you to other registrars, or they
might refer you to a 'rwhois' server.

For domain names, it's a LOT more complicated. ISO-3166 (two letter country
code) domains can often be found using the five RIRs. Dot coms/net/org/edu
(meaning .com, .net, and so on) should start at IANA, which will identify
the whois server of the domain registrar to contact. .org, .info, .biz, and
the like are much more fun.

[compton ~]$ grep -v '^[A-Z][A-Z] ' domains | column
AERO BIZ COM EDU INFO JOBS MOBI NAME ORG TRAVEL
ARPA CAT COOP GOV INT MIL MUSEUM NET PRO
[compton ~]$

http://www.iana.org/gtld/gtld.htm provides a miniscule more information on
these domains, and what they are used for.

Old guy
 
Reply With Quote
 
Kenneth
Guest
Posts: n/a

 
      09-21-2006, 09:22 PM
(E-Mail Removed) wrote:
> Hi All,
>
> I am trying to stop unauthorized traffic to and from GoToMyPC (and
> a list
> of others). How to I figure out GoToMyPC's network for my iptables
> "-d xxx.xxx.xxx.0/24" entry? (...0/24 may not always be the case,
> depending
> on subnet mask.)


http://www.citrixonline.com/iprange
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
using my network can i find out what is going through it?? aussie bongo Wireless Internet 3 06-24-2006 09:11 PM
Open source equivalent to gotomypc.com? ben@peikes.com Linux Networking 1 03-09-2006 12:01 AM
Can't find network john smith Wireless Internet 1 08-11-2004 10:40 PM
how do i find out where what network? ron sanders Wireless Internet 0 02-09-2004 02:37 AM
linux and gotomypc.com service Ted Potter Linux Networking 2 12-29-2003 12:37 PM



1 2 3 4 5 6 7 8 9 10 11