Friday, December 16, 2011

Need help on IP address lookup?

My 3rd-4th time receiving an email saying i signed up for some web cams which I know i didn't. I need more of an understanding what an IP address and how can you tell whether they're from the same person.


This is the email header I received





X-Apparently-To: moe_vang@yahoo.com via 67.195.8.137; Fri, 05 Feb 2010 05:05:11 -0800


Return-Path: %26lt;confirm-return-moe_vang=yahoo.com@ret鈥?br>

X-YMailISG: 1gqRxS8WLDvbsdm18RzPS_cuRlloyxpPRIbiyu鈥?br>

X-Originating-IP: [66.163.168.152]


Authentication-Results: mta1021.mail.mud.yahoo.com from=yahoogroups.com; domainkeys=pass (ok)


Received: from 127.0.0.1 (HELO n38b.bullet.mail.sp1.yahoo.com) (66.163.168.152) by mta1021.mail.mud.yahoo.com with SMTP; Fri, 05 Feb 2010 05:05:11 -0800


DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoogroups.com; s=lima; t=1265375110; bh=krQ8r1lEfTN/oAnTtoRa8yRzRFFzoQHi33K1j鈥?h=Received:Received:Date:Message-ID:X-Ya鈥?b=l+vLP8NaEEM36ErKptDNNT1rjbXunSN6Ficgro鈥?br>

DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=lima; d=yahoogroups.com; b=jN5tTJzJM3Jjkv/nFnJzjabLHVF41iwNkzs2jr鈥?br>

Received: from [69.147.65.147] by n38.bullet.mail.sp1.yahoo.com with NNFMP; 05 Feb 2010 13:05:10 -0000


Received: from [98.137.34.73] by t10.bullet.mail.sp1.yahoo.com with NNFMP; 05 Feb 2010 13:05:10 -0000


Date: 5 Feb 2010 13:05:10 -0000


Message-ID: %26lt;1265375110.303.11104.w7@yahoogroups.c鈥?br>

X-Yahoo-Newman-Property: groups-unconfirmed


From: This sender is DomainKeys verified


Yahoo! Groups %26lt;confirm-s2-gxkob0gebcq4l30guazyft0idzx1鈥?


Add sender to Contacts


Reply-To: confirm-s2-gxkob0gebcq4l30guazyft0idzx鈥?br>

To: moe_vang@yahoo.com


Subject: Please confirm your request to join MyHotWebcamClub02


MIME-Version: 1.0


Content-Type: text/plain


Content-Transfer-Encoding: 7bit


Content-Length: 836








From that, I'm somewhat suspecting someone who manual signs me up for crap like web cams and some of her IP address came from the same place which in example.....





68.180.197.159 UNITED STATES CALIFORNIA SUNNYVALE 37.3779


-122.027 94089 -08:00


Net Speed ISP Domain


DSL YAHOO! INC YAHOO.COM


IDD Code Area Code Weather Station


1 408/650 (USCA1116) SUNNYVALE





If anyone can help me, PLEASE, do. Thanks so much guys! I'm just really getting tired one after another blocking the emails and still receiving them.|||You already found out all the information you can really find out from someones IP address. If they are not using a STATIC IP provided to them by their internet service provider, then the perp is able to change his/her IP address whenever. You can, however, report the IP to their internet service provider and have them block all interactions with your IP.|||Unfortunately, the email headers that you sent do not have the information about who initiated the account on the service.





The only way that you would be able to do that is to contact the web site owners and complain to them. They probably will not tell you the IP address of the person that did it, but they will remove the account creation attempt and may work to block the person from doing it again in the future.|||IP Address can easily be changed in few minutes (using proxy to hide real IP address). What I would recommend is clicking on Report Spam button on your yahoo mail page. This would make yahoo add the sender to block list and all messages would go to spam folder.





Tip: Even if you find there real IP, you may not know who it is exactly. So no point in trying to match IP Address.|||I tried with


http://www.ipaddresslocation.org/email-t鈥?/a>


http://www.find-ip-address.org/email-sea鈥?/a>





Below is what both free email tracking tools show:


-------------------------------------


Email Header Analysis





Sender IP Address: 98.137.34.73 WhoIs Lookup IP BlackList Lookup


Host Addres: w7.grp.sp2.yahoo.com





Additional IP Information About Email Sender





IP Address Country: United States


IP Address City Location: Sunnyvale


IP Address Region: California


IP Address Latitude: 37.4249,


IP Address Longtitude: -122.0074


Organization: YAHOO


ISP: YAHOO


----------------------------





It looks as Yahoo by default hide IP address from email sender. There is nothing that you can do about it.

No comments:

Post a Comment