Networking Forums

Networking Forums > Computer Networking > Linux Networking > howto determine souce of hack attempt

Reply
Thread Tools Display Modes

howto determine souce of hack attempt

 
 
Eric
Guest
Posts: n/a

 
      12-19-2003, 05:31 AM
I've got a guy trying to spoof my network, i cant tell what his IP is as it
only appears to be the IP of my router. Somehow he has learned the name of
one of my systems and he is pretending to be that system, of course it
doesnt work but its anoying. I really need some help to track this down so
i can report him to his ISP.
Thanks
Eric
 
Reply With Quote
 
 
 
 
Michael Fuhr
Guest
Posts: n/a

 
      12-19-2003, 06:54 AM
Eric <(E-Mail Removed)> writes:

> I've got a guy trying to spoof my network, i cant tell what his IP is as it
> only appears to be the IP of my router. Somehow he has learned the name of
> one of my systems and he is pretending to be that system, of course it
> doesnt work but its anoying. I really need some help to track this down so
> i can report him to his ISP.


If you have a suspect in mind and you know who their provider is,
then you could ask that provider to investigate the matter. Otherwise
you'll probably have to do a hop-by-hop trace of the inbound packets,
that is, find out what router is sending the packets to you, then
find out what router is sending the packets to that router, and so
on and so on, until you find the origin. You'll probably need the
cooperation of several service providers, which you'll almost
certainly never get. If you can convince a judge that the law is
being broken then you might be able to get a court order, but even
then there are probably all sorts of difficulties if state or
national borders are being crossed.

An alternative method is described in the paper "Tracing Anonymous
Packets to Their Approximate Source" by Hal Burch and Bill Cheswick:

http://www.usenix.org/publications/l...ch/burch_html/

While interesting, the described technique makes certain assumptions
and has problems of its own, and the ability to pull it off is
probably beyond most people.

--
Michael Fuhr
http://www.fuhr.org/~mfuhr/
 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Howto determine if a system is using DHCP or STATIC IP shcodip Linux Networking 8 03-21-2007 03:21 AM
Attempt to breakin YouCanToo Linux Networking 20 07-13-2005 08:28 AM
inpcb or tcpcb in Linux net souce code Soohyun Cho Linux Networking 1 05-21-2004 10:34 PM
Hack attempt on Apache inst't it ? charly Linux Networking 6 12-16-2003 05:06 PM
Ethernet-Howto and Networking-Howto, etc... Bernard DEBREIL Linux Networking 0 11-27-2003 10:16 PM



1 2 3 4 5 6 7 8 9 10 11