Tilted Forum Project Discussion Community  

Go Back   Tilted Forum Project Discussion Community > Interests > Tilted Technology


 
 
LinkBack Thread Tools
Old 08-23-2003, 12:29 PM   #1 (permalink)
Riiiiight........
 
How do i find out who owns this IP?

Received: from ACNT-SPARE (168-215-59-34.gen.twtelecom.net [168.215.59.34])

or at least get in touch with someone that could help. This bugger has been flooding my email with sobig emails. 3000 in 3 days, at last count.

My school account kinda 'filters' it out, by deleting the attachments, and labelling the subject, so I can filter it out using my mail client. BUT i just want this to stop. It's flooding my trash, and not to mention the bounced msgs that i keep getting.

HELP!!

thanks...
dimbulb is offline  
Old 08-23-2003, 01:06 PM   #2 (permalink)
God-Hating Liberal
 
Location: Silicon Valley, CA
You don't. You should mail abuse@twtelecom.net
__________________
Nizzle
Nizzle is offline  
Old 08-23-2003, 02:21 PM   #3 (permalink)
Pro Libertate
 
Location: City Gecko
This is an IP tracker:

Track My IP

Enter the IP...

But they prob. spoofed it!
__________________
[color=bright blue]W[/color]e Stick To Glass

"If three of us travel together, I shall find two teachers."
Confucious

Mad_Gecko is offline  
Old 08-23-2003, 05:05 PM   #4 (permalink)
Crazy
 
Location: Upstate NY
its not spoofed, thats the ip of it, it only spoof's email addresses.
__________________
I am jack's broken heart
silenced is offline  
Old 08-23-2003, 05:07 PM   #5 (permalink)
Psycho
 
Or <a href="http://www.whois.net/">whois</a>. Try <a href="http://www.firetrust.com/index.php">this email program</a> that will put that ip on a blacklist. But you really need to report it to Spamcop also. The will want you to forward the emails (headers intact) and they will check it out.
poof is offline  
Old 08-23-2003, 05:37 PM   #6 (permalink)
Hello, good evening, and bollocks.
 
Fearless_Hyena's Avatar
 
Location: near DC
If I remember correctly, the Sobig email addresses are spoofed so that may not be the actual address where they came from.

However, SamSpade:
http://www.samspade.org

is a good site for learning about IP addresses.

definitely contact twtelecom.net's abuse department tho too, they might be able to help.
Fearless_Hyena is offline  
Old 08-23-2003, 06:39 PM   #7 (permalink)
God-Hating Liberal
 
Location: Silicon Valley, CA
ARIN whois information, traceroutes and the like are not going to do you any good. Even if you were, hypothetically, able to track it to someone's home address, what would you do? Go beat them up?

The proper thing to do is to block the IP of the SMTP server with a firewall and either wait it out, or send mail to abuse@twtelecom.net to speed it up.

To clear a bit of misinformation about SoBig: It spoofs the "From:" header in the email. The header of an email is supplied by the sender and can be set to anything you want it to be, provided the mail client gives you the option.

SoBig is unable to spoof an IP address.

Spoofing the src header of a TCP packet is possible, but the handshake-style negotiation would make it impossible to do this over the Internet. The spoofer would need access to your LAN and some sophisticated tools.
__________________
Nizzle
Nizzle is offline  
Old 08-24-2003, 10:18 AM   #8 (permalink)
Upright
 
This from Arin.net's whois on the address you specified. From it, the proper place to contact is abuse@twtelecom.net

Make sure you forward a copy with complete headers attached.
  • OrgName: Time Warner Telecom
    OrgID: TWTC
    Address: 10475 Park Meadows Drive
    City: Littleton
    StateProv: CO
    PostalCode: 80124
    Country: US

    NetRange: 168.215.0.0 - 168.215.255.255
    CIDR: 168.215.0.0/16
    NetName: TWTELECOM-COM
    NetHandle: NET-168-215-0-0-1
    Parent: NET-168-0-0-0-0
    NetType: Direct Allocation
    NameServer: NS1.MILW.TWTELECOM.NET
    NameServer: NS1.IPLT.TWTELECOM.NET
    NameServer: NS1.ORNG.TWTELECOM.NET
    Comment:
    RegDate: 2000-11-28
    Updated: 2001-09-26

    TechHandle: ZT87-ARIN
    TechName: Time Warner Telecom
    TechPhone: +1-800-898-6473
    TechEmail: ipmanager@twtelecom.net

    OrgAbuseHandle: TWTAD-ARIN
    OrgAbuseName: Time Warner Telecom Abuse Desk
    OrgAbusePhone: +1-800-898-6473
    OrgAbuseEmail: abuse@twtelecom.net

    OrgNOCHandle: TDN1-ARIN
    OrgNOCName: TWTC Data NOC
    OrgNOCPhone: +1-800-898-6473
    OrgNOCEmail: support@twtelecom.net

    OrgTechHandle: NST12-ARIN
    OrgTechName: NOC SWIP Team
    OrgTechPhone: +1-800-898-6473
    OrgTechEmail: swip@twtelecom.com

    # ARIN WHOIS database, last updated 2003-08-23 19:15
    # Enter ? for additional hints on searching ARIN's WHOIS database.
MMM-A is offline  
 

Tags
find, owns


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -8. The time now is 02:08 PM.

Tilted Forum Project

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0 PL2
© 2002-2012 Tilted Forum Project

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47