Home > Security Tips > Web Security Advisor > Computer forensics: Tracking an offender
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

WEB SECURITY ADVISOR

Computer forensics: Tracking an offender


InformIT
12.10.2002
Rating: -4.54- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Did you know there are many ways in which you can legally prosecute intruders with the evidence you uncover while tracking them? This excerpt from an InformIT article on tracking cyber criminals also provides a nice list of resources for pairing an actual identity with a numeric IP address.


Web resources for researching Internet inhabitants

International Registries

Three international organizations are responsible for the administration of IP addresses within their region, so they should be considered definitive sources. Each of these organizations has a Web site that provides a whois interface, in addition to other information helpful in locating the owner of a specific IP address:

Network diagnostic and research sites

  • Adhoc IP Tools: This site is a veritable Swiss Army knife of Internet tools, providing front ends to a wide variety of research services (whois, nslookup, ping, DNS dig and others), all accessed from a single page: http://home.ag.org/iptools.htm.
  • Sam Spade: Also provides a wide variety of research tools, http://www.samspade.org.
  • Internet Service Provider lookup: Enables you to search for ISPs by name, providing a summary of their business characteristics, http://www.webisplist.com.
  • Dragon Star: Provides an index, relating IP network numbers to network names and identities. It also includes a handy explanation of the IP address numbering scheme and describes the difference between Class A, B and C networks, http://ipindex.dragonstar.net/index.html.

News and e-mail abuse information

  • The spamfaq or "Figuring out fake e-mail & posts": This site, maintained by Gandalf@digital.net, is the most comprehensive source we're aware of. It has detailed instructions on how to track both e-mail and news, how to read the message headers in a dozen different mail clients and how to reach the appropriate abuse contact. It also has a huge number of additional links. It isn't edited well, but it is worth your time if you really need to understand message headers, http://ddi.digital.net/~gandalf/spamfaq.html.
  • Fighting E-mail Spammers: A site maintained by Todd Burgess, it is an excellent source of information on tracking e-mail, http://eddie.cis.uoguelph.ca/tburgess/local/spam.html.
  • Fight Spam on the Internet!: Another site with a number of links on the subject of unsolicited e-mail, http://spam.abuse.net/.
  • Reading E-Mail Headers: A detailed explanation of the function of dozens of different e-mail headers, http://www.stopspam.org/email/headers/headers.html.

Read more about the methods of tracking intruders at InformIT. Registration is required, but it is free.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.


Submit a Tip




BROWSE BY TAG
Web Security Advisor,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Web Security Advisor
DNS rebinding defenses still necessary, thanks to Web 2.0
New defenses for automated SQL injection attacks
PCI compliance and Web applications: Code review or firewalls?
Worst practices: Bad security incidents to avoid
Web scanning and reporting best practices
Social networking Web site threats manageable with good enterprise policy
Enterprise security in 2008: Building trust into the application development process
PCI DSS Section 6: A plan for tackling application security
Making the case for Web application vulnerability scanners
Preparing for uniform resource identifier (URI) exploits

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts