IP Addresses & All That Stuff

From RWDWiki

(Difference between revisions)
Jump to: navigation, search
 
(244 intermediate revisions not shown)
Line 1: Line 1:
-
<CENTER><H1>IP Addresses & All That Stuff</H1><i>A Mini-Tutorial contributed by Sandro43, Shadow & Dan</i>
+
<CENTER><i>A Mini-Tutorial contributed by Sandro43, Shadow, Dewed & Dan</i></CENTER>
-
</CENTER>
+
-
<H3>1. What's IP?</H3>
+
A discussion occasionally arises in some RWD thread about <u><b>IP addresses</b></u> and <u><b>E-mail Headers</b></u>, usually when wondering about the possible origin of some dubious letter from an FSUW.  
-
A discussion occasionally arises in some RWD thread about <u><b>IP addresses</b></u>, usually when wondering about the possible origin of some dubious E-mail from an FSUW. This discussion aims at clarifying some basic aspects of this mystery.
+
-
The <b>IP</b> acronym stands for <b>Internet Protocol</b>. A network communications <i>protocol</I> is a set of conventions, rules, etc. governing the exchange of data between network entities, much like a language is - you have to share the <u>same</u> language to make yourself understood by someone else - and in fact uses a lot of linguistic terminology like <i>command <u>syntax</u>, command <u>verbs</u></i> and so on. <p>The <b>Internet Protocol</b> is the basis upon which all Internet communications occur, be they accessing an Internet website (TCP/IP), sending/receiving mail (SMTP/IP), making an Internet file transfer (FTP/IP), and so on.
+
What follows aims at clarifying some basic aspects of the subject.
-
An <b>IP address</b> is what <u>uniquely</u> identifies someone/something communicating over the Internet network, and has that weird-looking numerical form (like RWD's <font color=blue>67.222.30.14</font>) belying the actual antiquity of the Internet, born in the 1960s at the initiative of the US Department of Defense's Advanced Research Projects Agency (DARPA).
 
-
<H3>2. Who creates an IP address?</H3>
+
 
-
In order to access the Internet, first you have to obtain the services of an <b>Internet Provider</b>, usually through a paid subscription. <p>In order to operate, your Internet Provider must in turn have previously aquired the permission to use a unique set of IP addesses (<i>IP range</i>) from his 'regional' authority, one of the following depending on geographical location:
+
== What's IP? ==
 +
 
 +
The '''IP''' acronym stands for '''Internet Protocol'''. A communications ''protocol'' is a set of conventions, rules, etc. governing the exchange of data between network entities, much like a language is - you have to share the <u>same</u> language to make yourself understood by someone else you are communicating with.  
 +
 
 +
The '''Internet Protocol''' is the basis upon which all Internet communications occur, be they accessing an Internet website (TCP/IP), sending/receiving mail (SMTP/IP), making an Internet file transfer (FTP/IP), and so on.
 +
 
 +
An '''IP address''' is what <u>uniquely</u> identifies someone/something communicating over the Internet network, and has that weird-looking numerical form (like RWD's <font color=blue>'''67.222.30.14'''</font>) that belies the actual antiquity of the Internet, born in the 1960s at the initiative of the US Department of Defense's ''Advanced Research Projects Agency'' (DARPA).
 +
 
 +
== Who creates an IP address? ==
 +
 
 +
In order to access the Internet, first you have to obtain the services of an '''Internet Provider''', usually through a paid subscription.  
 +
 
 +
In order to operate, your Internet Provider in turn must have previously acquired the authorisation to use a unique set of IP addesses (<i>IP range</i>) from its 'regional' authority, one of the following depending on geographical location:
<ul>
<ul>
<li>AfriNIC (Africa)
<li>AfriNIC (Africa)
Line 18: Line 27:
<li>RIPE (Europe, the Middle East and parts of Africa and Asia)
<li>RIPE (Europe, the Middle East and parts of Africa and Asia)
</ul>
</ul>
-
The Internet Provider  will allocate <b>one IP address</b> to a user requesting to log on the Internet on a first-come/first-served basis - i.e. a <b>dynamic</b> IP address, which means that the next time you log on, your IP address will probably be different from the one you are using now - although one always comprised within your Provider's assigned IP range.
+
The Internet Provider  will allocate '''one IP address''' from its 'pool' to a user requesting to log on to the Internet on a first-come/first-served basis - i.e. a '''dynamic''' IP address, which means that the next time you log on, your IP address will probably be different from the one you are using now - although one always comprised within your Provider's assigned IP range.
-
<CENTER>[[Image:C:\Documents and Settings\SANDRO\My Documents\RWD\IP\Untitled-1.gif]]</CENTER>
+
<CENTER>[[Image:Untitled-1.gif]]</CENTER>
-
Your PC needs this specific bit of information because, in compliance with the IP Protocol, it HAS to be included into ANY packet that it will subsequently send out over the Internet, i.e. in any network activity. Once you log off the Internet and hence your Provider, the same IP address that identified you may well be assigned to a different user now requesting to log on.
+
Your PC needs this specific bit of numerical information because, in compliance with the IP Protocol, it HAS to be included into ANY packet that it will subsequently send out over the Internet, i.e. in any network activity. Once you log off the Internet and hence from your Provider, the same IP address that identified you may well be assigned to a different user now requesting to log on.
-
You <i>could</i> log on to RWD by giving your browser the address <i><font color=blue>http://67.222.30.14</font></i>. However, this is obviously too cumbersome to contemplate and you will normally use <i><font color=blue>http://www.russianwomendiscussion.com</font></i> instead. This is possible because your Provider relies on a <b>Domain Name Server</b> (DNS) that stores tables where one entry will read something like:
+
You <i>could</i> access RWD by giving your browser the address <i><font color=blue><nowiki>http://67.222.30.14</nowiki></font></i>. However, this is obviously too cumbersome to contemplate and you will normally use <i><font color=blue><nowiki>http://www.russianwomendiscussion.com</nowiki></font></i> instead. This is possible because your Provider relies on a <b>Domain Name Server</b> (DNS) that stores tables where one entry will read something like:
-
<TABLE ALIGN=CENTER BORDER=1 CELLPADDING=5><TR><TD>http://www.russianwomendiscussion.com</TD><TD>67.222.30.14</TD></TR></TABLE>
+
<table align=center cellpadding=5 border=1><tr><TD><nowiki>www.russianwomendiscussion.com</nowiki><TD>67.222.30.14</td></tr></table>
-
The DNS allows your Provider to translate the RWD <i>symbolic address</i> that you wrote to its actual, <i>physical</i> IP address - which, incidentally, is a <b>fixed</b> IP address since RWD is its own only client.
+
The DNS allows your Provider to translate the RWD <i>symbolic</i> address that you wrote to its actual, <i>physical</i> IP address - which, incidentally, is a <b>fixed</b> IP address since RWD is its own only client - RWD member activity is managed at a higher, application level by the Forum SW.
-
<b>All the above implies that the IP address which you can see in the <i>header</i> of an E-mail you received, may only help you identify your correspondent's Internet Provider and its location, NOT that of its specific but temporary user.</b>
 
-
Nevertheless, this information may be of SOME use.
+
'''All the above implies that the IP address which you can see in the header of an E-mail you received, may only help you identify <u>your correspondent's Internet Provider and its location</u>, NOT that of its specific but temporary user.'''
-
<H3>3. The E-mail Header</H3>
 
-
Sending/receiving electronic mail via the Internet involves additional participants - the <b>Mail Servers</b> - which may not necessarily reside in the same geographical locations as the Internet providers' - just to cite some examples, the <i>Yahoo Mail</i> and <i>Google Mail</i> servers are located in the USA but have mail clients from all over the world.
 
-
<CENTER><img src=Untitled-2.gif></CENTER>
 
-
An E-mail header contains information on ALL the HW participants to the exchange, as well as on the SW participants, i.e. the PC-resident <b>Mail Programs</b> - such as <i>MS Outlook</i> - and any installed <i>anti-virus/anti-spam</i> SW.
 
-
The following is the example of an E-mail I received from a highly suspect FSU girl - with decidedly marginal English capabilities:
+
Furthermore, many hackers, spammers and some sophisticated scammers mask their identity/location by interposing a <b>Proxy Server</b> (see http://en.wikipedia.org/wiki/Proxy_server) between their PC and their Internet Provider.
 +
 
 +
Nevertheless, the information contained in a header may yet be of SOME use.
 +
 
 +
== The E-mail Header ==
 +
 
 +
Sending/receiving electronic mail via the Internet involves additional participants - the <b>Mail Servers</b> that make electronic <i>mailboxes</i> available. These services may be offered by the Internet Providers themselves or by some independent entity, in which case they do not necessarily reside in the same geographical location - just to mention some examples, the <i>Yahoo Mail</i> and <i>Google Mail</i> servers are located in the USA but have mail clients from all over the world.
 +
<CENTER>[[Image:Untitled-2.gif]]</CENTER>
 +
An E-mail header contains information on ALL the HW participants to the exchange, as well as on the SW participants, i.e. the PC-resident <b>Mail Programs</b> - such as <i>MS Outlook</i> - and any installed <i>anti-virus/anti-spam</i> SW that may filter your E-mail.
 +
 
 +
The header is the 'service' part of an E-mail and therefore is not normally visible: use the <i>Help</i> function of your Mail Program to learn how it can be made to appear - in MS Outlook, for instance, use the <i>View</i> menu, click <I>Layout</i> and select an option of <i>Preview Pane</i>.
 +
 
 +
The following is the example of an E-mail that I received from a highly suspect FSU girl - with decidedly marginal English capabilities:
<table ALIGN=CENTER><TR><TD><font size=2><I>From: dinalove1977@rambler.ru<br>To: sanfloriani@alice.it
<table ALIGN=CENTER><TR><TD><font size=2><I>From: dinalove1977@rambler.ru<br>To: sanfloriani@alice.it
-
Subject: [spam] Hollo the stranger!!<br>Hollo the stranger!!<br>I saw your profile on a site of acquaintances, and you very persistently it was pleasant to me,<br>and I carelessly saw yours Send by e-mail the address, and have decided to write you the letter,<br>and to send a photo and if I was pleasant To you That you can write to me,<br>and I will rejoice very much to it if you answer me, but my letter if you wish,<br>but to Look my profile, that he names in me Dina. I do not know,<br>that to you while to write and I to you I promise, whether you answer me my letter it in other<br>The letter is good??? To you I will write not so on more. I expect from you the letter<br>sincerely yours Dina!!<br>PS you can write me on this email dinalove1977@rambler.ru address.</I></font></table>
+
Subject: <spam> Hollo the stranger!!<br>Hollo the stranger!!<br>I saw your profile on a site of acquaintances, and you very persistently it was pleasant to me,<br>and I carelessly saw yours Send by e-mail the address, and have decided to write you the letter,<br>and to send a photo and if I was pleasant To you That you can write to me,<br>and I will rejoice very much to it if you answer me, but my letter if you wish,<br>but to Look my profile, that he names in me Dina. I do not know,<br>that to you while to write and I to you I promise, whether you answer me my letter it in other<br>The letter is good??? To you I will write not so on more. I expect from you the letter<br>sincerely yours Dina!!<br>PS you can write me on this email dinalove1977@rambler.ru address.</I></font></table>
 +
 
 +
And this is its header - in tabular form with comments (information in <font color=blue>blue</font> was obtained with the tools listed below):
-
And this is its header - in tabular form with comments (information in <font color=blue>blue</font> was obtained with the tools listed in item 4 below):
 
<table border=1 align=center WIDTH=800>
<table border=1 align=center WIDTH=800>
<tr>
<tr>
-
<td VALIGN=TOP><<font size=2>X-Persona: ALICE
+
<td VALIGN=TOP><font size=2>X-Persona: ALICE
-
<td><font size=2>My <b>Mail Server</b> (alice.it). <b>X</b> is a time-honored acronym for <i>message</i>.
+
<td><font size=2>My <b>Mail Server</b> (@alice.it). <b>X</b> is a time-honored acronym for <i>message</i>.
<tr>
<tr>
-
<td VALIGN=TOP><font size=2>Received: from FBCMMI01B08.fbc.local ([<font color=red>192.168.171.30</font>])<BR>by FBCMST14V04.fbc.local with Microsoft SMTPSVC(6.0.3790.3959);<BR>Fri, 14 May 2010 03:34:26 +0200
+
<td VALIGN=TOP><font size=2>Received: from FBCMMI01B08.fbc.local [<font color=red>192.168.171.30</font>] by FBCMST14V04.fbc.local with Microsoft SMTPSVC(6.0.3790.3959); Fri, 14 May 2010 03:34:26 +0200
-
<td ROWSPAN=2 VALIGN=TOP><font size=2>My Mail Server is operated by Italy's Telecom through their own internal, private network using MS SMTP Services:
+
<td ROWSPAN=2 VALIGN=TOP><font size=2>My Mail Server is operated by my <b>Internet Provider</b> (Telecom Italia) through their own internal, private network using MS SMTP (<i>Simple Mail Transfer Protocol</i>) Services. IP addresses 192.168.171.30, 192.168.69.32 resolve to:
-
<br><br><font color=blue>
+
<font color=blue>
-
inetnum:         192.168.0.0 - 192.168.255.255
+
inetnum: 192.168.0.0 - 192.168.255.255<BR>netname: IANA-CBLK-RESERVED1<BR>descr: <b>Class C address space for private internets</b><BR>country: EU # Country is really world wide</font>
-
<BR>netname:         IANA-CBLK-RESERVED1
+
<P>Italy's Summer Time is +02:00 hours GMT.
-
<BR>descr:           <b>Class C address space for private internets</b>
+
-
<BR>country:         EU # Country is really world wide</font>
+
-
<P>Italy's summer time is +02.00 hours later than GMT.
+
<tr>
<tr>
-
<td VALIGN=TOP><font size=2>Received: from FBCMMX01B03.fbc.local ([<font color=red>192.168.69.32</font>])
+
<td VALIGN=TOP><font size=2>Received: from FBCMMX01B03.fbc.local [<font color=red>192.168.69.32</font>] by FBCMMI01B08.fbc.local with Microsoft SMTPSVC(6.0.3790.3959); Fri, 14 May 2010 03:34:27 +0200
-
<BR>by FBCMMI01B08.fbc.local with Microsoft SMTPSVC(6.0.3790.3959);
+
-
<BR>Fri, 14 May 2010 03:34:27 +0200<
+
<tr>
<tr>
-
<td VALIGN=TOP><font size=2>Received: from <font color=red>maild.rambler.ru ([81.19.66.33])</font>
+
<td VALIGN=TOP><font size=2>Received: from <font color=red>maild.rambler.ru [81.19.66.33]</font> by FBCMMX01B03.fbc.local with Microsoft SMTPSVC(6.0.3790.3959); Fri, 14 May 2010 03:34:24 +0200
-
<BR>by FBCMMX01B03.fbc.local with Microsoft SMTPSVC(6.0.3790.3959);
+
<td VALIGN=TOP><font size=2>My Mail Server received the E-mail from Dina's <b> Mail Server</b> (rambler.ru), whose 81.19.66.33 IP address resolves to:<font color=blue><BR>inetnum: 81.19.64.0 - 81.19.66.255<BR>netname: RAMTEL<BR>descr: Rambler main network<BR>country: RU<BR>address: "Rambler Internet Holding" OJSC<BR>address: 3 floor, Leninskaya Sloboda st., 19, Omega Plaza<BR>address: Moscow, RU
-
<BR>Fri, 14 May 2010 03:34:24 +0200
+
-
<td VALIGN=TOP><font size=2>My Mail Server received the E-mail from Dina's <b> Mail Server</b> (rambler.ru), whose 81.19.66.33 IP address resolves to:<font color=blue>
+
-
<BR>inetnum:         81.19.64.0 - 81.19.66.255
+
-
<BR>netname:         RAMTEL
+
-
<BR>descr:           Rambler main network
+
-
<BR>country:         RU
+
-
<BR>address:         "Rambler Internet Holding" OJSC
+
-
<BR>address:         3 floor, Leninskaya Sloboda st., 19, Omega Plaza
+
-
<BR>address:         Moscow, RU
+
<tr>
<tr>
-
<td VALIGN=TOP><KBD><font size=2>Received: from max (unknown [<font color=red>77.40.33.85</font>])
+
<td VALIGN=TOP><font size=2>Received: from max [unknown <font color=red>77.40.33.85</font>]
-
<td><font size=2>Dina's <b> Internet Provider</b> , whose 77.40.33.85 IP address resolves to:<font color=blue>
+
<td><font size=2>Dina's <b> Internet Provider</b>, whose 77.40.33.85 IP address resolves to:<font color=blue><BR>inetnum: 77.40.8.0 - 77.40.79.255<BR>netname: MARI-VOLGATELECOM<BR>address: VolgaTelecom Mari El branch<BR>address: Sovetskaya 138<BR>address: 424000 Yoshkar-Ola<BR>ISP: XDSL DYNAMIC POOLS<BR>Net Speed: DSL</font>
-
<BR>inetnum:       77.40.8.0 - 77.40.79.255
+
-
<BR>netname:       MARI-VOLGATELECOM
+
-
<BR>address:       VolgaTelecom Mari El branch
+
-
<BR>address:       Sovetskaya 138
+
-
<BR>address:       424000 Yoshkar-Ola
+
-
<BR>ISP: XDSL DYNAMIC POOLS
+
-
<BR>Net Speed: DSL</font>
+
<tr>
<tr>
-
<td VALIGN=TOP><font size=2>(Authenticated sender: dinalove1977@rambler.ru)
+
<td VALIGN=TOP><font size=2>(Authenticated sender: dinalove1977@rambler.ru) by maild.rambler.ru <font color=red>(Postfix)</font> with ESMTP id 919608441E for <sanfloriani@alice.it>; Fri, 14 May 2010 05:34:22 +0400 (MSD)<BR>Date: Thu, 13 May 2010 19:18:57 +0400<BR>From: dinalove1977@rambler.ru
-
<BR>by maild.rambler.ru <font color=red>(Postfix)</font> with ESMTP id 919608441E
+
<td VALIGN=TOP><font size=2>Dina's <b>Mail Server</b> runs on an open-source Unix E-mail server (Postfix) using <i>Extended SMTP</i>.<br>Dina logged on correctly there on Thu, 13 May 2010 at 19:18:57 +0400<br>Her E-mail was sent out on Fri, 14 May 2010 at 05:34:22 +0400 (MSD)<br>MSD mean Moscow Summer Time, +04:00 hours GMT.
-
<BR>for <sanfloriani@alice.it>; Fri, 14 May 2010 05:34:22 +0400 (MSD)
+
-
<BR>Date: Thu, 13 May 2010 19:18:57 +0400
+
-
<BR>From: dinalove1977@rambler.ru
+
-
<td VALIGN=TOP><font size=2>Dina's <b>Mail Server</b> runs on an open-source E-mail server for Unix (Postfix).
+
-
<br><br>She logged on correctly there on Thu, 13 May 2010 at 19:18:57 +0400
+
-
<br>Her E-mail was sent out on Fri, 14 May 2010 at 05:34:22 +0400 (MSD)
+
-
<br><br>MSD mean Moscow Summer Time, +0400 hours later than GMT.
+
<tr>
<tr>
-
<td VALIGN=TOP><font size=2><font color=red>X-Mailer: The Bat!</font>  (v1.62r) UNREG / CD5BF9353B3B7091
+
<td VALIGN=TOP><font size=2><font color=red>X-Mailer: The Bat!</font>  (v1.62r) UNREG / CD5BF9353B3B7091<BR>Reply-To: dinalove1977@rambler.ru<BR>X-Priority: 3 (Normal)<BR>Message-ID: <1136748830.20100513191857@rambler.ru><BR>To: sanfloriani@alice.it<BR>Subject: <spam] Hollo the stranger!!<BR>MIME-Version: 1.0<BR>Content-Type: multipart/mixed; boundary="----------119EE621096919"<BR>Return-Path: dinalove1977@rambler.ru
-
<BR>Reply-To: dinalove1977@rambler.ru
+
<td VALIGN=TOP><font size=2>Dina's <b> Mail Program</b> (The Bat!)
-
<BR>X-Priority: 3 (Normal)
+
The Bat! is the most popular FSU mail program, in this case an UNREGistered copy for personal use.
-
<BR>Message-ID: <1136748830.20100513191857@rambler.ru>
+
The registered copy allows for mass-mailing and is a favorite tool of spammers.<br><br>A MIME (Multipurpose Internet Mail Extensions) <I>Content-Type: multipart/mixed</I> means Dina's E-mail was text plus attachments - a photo:<br><CENTER>[[Image:Dina.jpg]]</CENTER>
-
<BR>To: sanfloriani@alice.it
+
-
<BR>Subject: [spam] Hollo the stranger!!
+
-
<BR>MIME-Version: 1.0
+
-
<BR>Content-Type: multipart/mixed;
+
-
<BR>boundary="----------119EE621096919"
+
-
<BR>Return-Path: dinalove1977@rambler.ru
+
-
<td VALIGN=TOP><font size=2>Dina's <b> Mail Program</b> (The Bat!)
+
-
<p>The Bat! is the most popular FSU mail program, in this case an UNREGistered copy for personal use.
+
-
The registered copy allows for mass-mailing and is a favorite tool of spammers.
+
-
<BR><BR><BR><BR>A MIME (Multipurpose Internet Mail Extensions) <I>Content-Type: multipart/mixed</I> means Dina's E-mail was text plus attachments (a photo).
+
<tr>
<tr>
-
<td VALIGN=TOP><font size=2>X-OriginalArrivalTime: 14 May 2010 01:34:25.0018 (UTC)
+
<td VALIGN=TOP><font size=2>X-OriginalArrivalTime: 14 May 2010 01:34:25.0018 (UTC) FILETIME=<95FBE5A0:01CAF305]<br><font color=red>X-Antivirus: AVG for E-mail 9.0.819</font> [271.1.1/2869]<BR>X-Text-Classification: spam<BR><font color=red>X-POPFile</font>-Link: <nowiki>http://127.0.0.1:8080/jump_to_message?view=131</nowiki>
-
<BR>FILETIME=[95FBE5A0:01CAF305]
+
<td VALIGN=TOP><font size=2>My Mail Server received Dina's E-mail 3 seconds later on 14 May 2010 at 01:34:25.0018 (UTC) - UTC or CUT is Coordinated Universal Time.<br>My anti-virus  program (AVG)<BR>and<BR>my anti-spam program (POP File), which judiciously classified Dina's E-mail as spam.
-
<p>X-Antivirus: AVG for E-mail 9.0.819 [271.1.1/2869]
+
-
<BR>X-Text-Classification: spam
+
-
<BR>X-POPFile-Link: http://127.0.0.1:8080/jump_to_message?view=131
+
-
<td VALIGN=TOP><font size=2>My Mail Server received Dina's E-mail<BR>on 14 May 2010 at 01:34:25.0018 (UTC)
+
-
<br>UTC or CUT is Coordinated Universal Time.
+
-
<p>My anti-virus  program (AVG)<BR>and<BR>my anti-spam program (POP File), which judiciously classified Dina's E-mail as spam.</td></tr></table>
+
-
<H3>4. Helpful Tools</H3>
+
<tr><td colspan=2>
-
To resolve an IP address:
+
 
-
<br>- <a href=http://www.dnsstuff.com/>DNS Stuff</a>
+
== Helpful Tools ==
-
<br>- <a href=http://whatismyipaddress.com/>What Is My IP Address</a>
+
-
<br>- <a href=http://www.geobytes.com/IpLocator.htm>Geobytes</a>
+
-
<br>- <a href=http://www.ip2location.com/demo.aspx>IP 2 Location</a>
+
To separate an E-mail header into more easily legible chunks:
To separate an E-mail header into more easily legible chunks:
-
<br>- <a href=http://www.mxtoolbox.com/EmailHeaders.aspx>MX Toolbox</a>
+
<ul>
 +
<li>MX Toolbox: http://www.mxtoolbox.com/EmailHeaders.aspx
 +
</ul>
 +
 
 +
 
 +
To resolve an IP address:
 +
<ul>
 +
<li>DNS Stuff: http://www.dnsstuff.com/
 +
<li>What Is My IP Address: http://whatismyipaddress.com/
 +
<li>Geobytes: http://www.geobytes.com/IpLocator.htm
 +
<li>Next Web Security: http://www.nextwebsecurity.com/HeaderTool2-pub.asp
 +
<li>IP 2 Location: http://www.ip2location.com/demo.aspx
 +
<li>Arul's Tech Info: http://aruljohn.com/info/howtofindipaddress/
 +
</ul>
 +
 
 +
 
 +
Most of the above tools access the regional authority databases through the WHO IS function, which you can do directly yourself:
 +
<ul>
 +
<li>Afrinic: http://www.afrinic.net/cgi-bin/whois
 +
<li>Apnic: http://wq.apnic.net/apnic-bin/whois.pl
 +
<li>Arin: http://ws.arin.net/whois
 +
<li>Lacnic: http://lacnic.net/cgi-bin/lacnic/whois
 +
<li>RIPE: http://www.db.ripe.net/whois
 +
</ul>
 +
 
 +
 
 +
Another useful tool in this area is <b>Tin Eye</b> (http://www.tineye.com/) where you can submit a photo from your PC or some Internet website, and it will tell you where else on the Internet, to its not infinite knowledge, that photo also appears, be it a dating site, a scammer-listing site or elsewhere.
 +
 
 +
 
 +
<tr><td colspan=2>
 +
 
 +
== Conclusions ==
-
<H3>5. Conclusions</H3>
 
What have we learned from decoding Dina's E-mail header information?
What have we learned from decoding Dina's E-mail header information?
<ul>
<ul>
<li>Dina uses a PC, and probably lives, in <b>Yoshkar-Ola</b>, a city as famous for scammers as Lugansk.
<li>Dina uses a PC, and probably lives, in <b>Yoshkar-Ola</b>, a city as famous for scammers as Lugansk.
-
<li>Her Internet Provider is the local <b>VolgaTelecom, Mari-El branch</b>, giving her a DSL connection with a dynamic IP address (<b>77.40.33.85</b>).
+
<li>Her Internet Provider is the local <b>VolgaTelecom, Mari-El branch</b>, giving her a DSL connection with a dynamic IP address (<b>77.40.33.85</b>). Given that private DSL is not as widely available in Russia as in the West, it MAY mean that Dina wrote her E-mail from a PC installed at some public facility (Internet Café, school, office, etc.)
-
<li>Her Mail Server is <b>Rambler.ru</b>, where she logged on at 19:18:57.
+
<li>Her Mail Server is Moscow's <b>Rambler.ru</b>.
-
<li>Her Mail Program is <b>The Bat!</b>, which queued her message for sending the following day at 05:34:22, 8 hours later.
+
<li>Her Mail Program is <b>The Bat!</b>.
</ul>
</ul>
-
----
+
 
-
'''Return to RWD''':
+
The above, and most of all her E-mail text, warrant further investigation.
-
* Home : http://www.RussianWomenDiscussion.com
+
 
-
* Forum : http://www.russianwomendiscussion.com/index.php
+
<b>Google</b> can be a great aid in this - Dina's E-mail address <b>dinalove1977@rambler.ru</b> produces a page on the Zoqy Net blog (http://zoqy.net/?p=1734) written by a French wine lover who also received the SAME letter and photo a week earlier on May 10 through Yahoo Mail.
 +
 
 +
Therefore, Dina is very likely a scammer with a penchant for European Latins :-))
 +
 
 +
Further hints on how to spot a scammer can be obtained from RWD's <b>Scammer Score Card</b> (Scam Card: http://www.russianwomendiscussion.com/index.php?pid=34).

Latest revision as of 12:15, 29 April 2013

A Mini-Tutorial contributed by Sandro43, Shadow, Dewed & Dan

A discussion occasionally arises in some RWD thread about IP addresses and E-mail Headers, usually when wondering about the possible origin of some dubious letter from an FSUW.

What follows aims at clarifying some basic aspects of the subject.


Contents

What's IP?

The IP acronym stands for Internet Protocol. A communications protocol is a set of conventions, rules, etc. governing the exchange of data between network entities, much like a language is - you have to share the same language to make yourself understood by someone else you are communicating with.

The Internet Protocol is the basis upon which all Internet communications occur, be they accessing an Internet website (TCP/IP), sending/receiving mail (SMTP/IP), making an Internet file transfer (FTP/IP), and so on.

An IP address is what uniquely identifies someone/something communicating over the Internet network, and has that weird-looking numerical form (like RWD's 67.222.30.14) that belies the actual antiquity of the Internet, born in the 1960s at the initiative of the US Department of Defense's Advanced Research Projects Agency (DARPA).

Who creates an IP address?

In order to access the Internet, first you have to obtain the services of an Internet Provider, usually through a paid subscription.

In order to operate, your Internet Provider in turn must have previously acquired the authorisation to use a unique set of IP addesses (IP range) from its 'regional' authority, one of the following depending on geographical location:

  • AfriNIC (Africa)
  • APNIC (Asia Pacific region)
  • ARIN (North America, a portion of the Caribbean and sub-Saharan Africa)
  • LACNIC (Latin American and Caribbean region)
  • RIPE (Europe, the Middle East and parts of Africa and Asia)

The Internet Provider will allocate one IP address from its 'pool' to a user requesting to log on to the Internet on a first-come/first-served basis - i.e. a dynamic IP address, which means that the next time you log on, your IP address will probably be different from the one you are using now - although one always comprised within your Provider's assigned IP range.

Image:Untitled-1.gif

Your PC needs this specific bit of numerical information because, in compliance with the IP Protocol, it HAS to be included into ANY packet that it will subsequently send out over the Internet, i.e. in any network activity. Once you log off the Internet and hence from your Provider, the same IP address that identified you may well be assigned to a different user now requesting to log on.

You could access RWD by giving your browser the address http://67.222.30.14. However, this is obviously too cumbersome to contemplate and you will normally use http://www.russianwomendiscussion.com instead. This is possible because your Provider relies on a Domain Name Server (DNS) that stores tables where one entry will read something like:


www.russianwomendiscussion.com67.222.30.14


The DNS allows your Provider to translate the RWD symbolic address that you wrote to its actual, physical IP address - which, incidentally, is a fixed IP address since RWD is its own only client - RWD member activity is managed at a higher, application level by the Forum SW.


All the above implies that the IP address which you can see in the header of an E-mail you received, may only help you identify your correspondent's Internet Provider and its location, NOT that of its specific but temporary user.


Furthermore, many hackers, spammers and some sophisticated scammers mask their identity/location by interposing a Proxy Server (see http://en.wikipedia.org/wiki/Proxy_server) between their PC and their Internet Provider.

Nevertheless, the information contained in a header may yet be of SOME use.

The E-mail Header

Sending/receiving electronic mail via the Internet involves additional participants - the Mail Servers that make electronic mailboxes available. These services may be offered by the Internet Providers themselves or by some independent entity, in which case they do not necessarily reside in the same geographical location - just to mention some examples, the Yahoo Mail and Google Mail servers are located in the USA but have mail clients from all over the world.

Image:Untitled-2.gif

An E-mail header contains information on ALL the HW participants to the exchange, as well as on the SW participants, i.e. the PC-resident Mail Programs - such as MS Outlook - and any installed anti-virus/anti-spam SW that may filter your E-mail.

The header is the 'service' part of an E-mail and therefore is not normally visible: use the Help function of your Mail Program to learn how it can be made to appear - in MS Outlook, for instance, use the View menu, click Layout and select an option of Preview Pane.

The following is the example of an E-mail that I received from a highly suspect FSU girl - with decidedly marginal English capabilities:

From: dinalove1977@rambler.ru
To: sanfloriani@alice.it Subject: <spam> Hollo the stranger!!
Hollo the stranger!!
I saw your profile on a site of acquaintances, and you very persistently it was pleasant to me,
and I carelessly saw yours Send by e-mail the address, and have decided to write you the letter,
and to send a photo and if I was pleasant To you That you can write to me,
and I will rejoice very much to it if you answer me, but my letter if you wish,
but to Look my profile, that he names in me Dina. I do not know,
that to you while to write and I to you I promise, whether you answer me my letter it in other
The letter is good??? To you I will write not so on more. I expect from you the letter
sincerely yours Dina!!
PS you can write me on this email dinalove1977@rambler.ru address.

And this is its header - in tabular form with comments (information in blue was obtained with the tools listed below):


X-Persona: ALICE My Mail Server (@alice.it). X is a time-honored acronym for message.
Received: from FBCMMI01B08.fbc.local [192.168.171.30] by FBCMST14V04.fbc.local with Microsoft SMTPSVC(6.0.3790.3959); Fri, 14 May 2010 03:34:26 +0200 My Mail Server is operated by my Internet Provider (Telecom Italia) through their own internal, private network using MS SMTP (Simple Mail Transfer Protocol) Services. IP addresses 192.168.171.30, 192.168.69.32 resolve to:

inetnum: 192.168.0.0 - 192.168.255.255
netname: IANA-CBLK-RESERVED1
descr: Class C address space for private internets
country: EU # Country is really world wide

Italy's Summer Time is +02:00 hours GMT.

Received: from FBCMMX01B03.fbc.local [192.168.69.32] by FBCMMI01B08.fbc.local with Microsoft SMTPSVC(6.0.3790.3959); Fri, 14 May 2010 03:34:27 +0200
Received: from maild.rambler.ru [81.19.66.33] by FBCMMX01B03.fbc.local with Microsoft SMTPSVC(6.0.3790.3959); Fri, 14 May 2010 03:34:24 +0200 My Mail Server received the E-mail from Dina's Mail Server (rambler.ru), whose 81.19.66.33 IP address resolves to:
inetnum: 81.19.64.0 - 81.19.66.255
netname: RAMTEL
descr: Rambler main network
country: RU
address: "Rambler Internet Holding" OJSC
address: 3 floor, Leninskaya Sloboda st., 19, Omega Plaza
address: Moscow, RU
Received: from max [unknown 77.40.33.85] Dina's Internet Provider, whose 77.40.33.85 IP address resolves to:
inetnum: 77.40.8.0 - 77.40.79.255
netname: MARI-VOLGATELECOM
address: VolgaTelecom Mari El branch
address: Sovetskaya 138
address: 424000 Yoshkar-Ola
ISP: XDSL DYNAMIC POOLS
Net Speed: DSL
(Authenticated sender: dinalove1977@rambler.ru) by maild.rambler.ru (Postfix) with ESMTP id 919608441E for <sanfloriani@alice.it>; Fri, 14 May 2010 05:34:22 +0400 (MSD)
Date: Thu, 13 May 2010 19:18:57 +0400
From: dinalove1977@rambler.ru
Dina's Mail Server runs on an open-source Unix E-mail server (Postfix) using Extended SMTP.
Dina logged on correctly there on Thu, 13 May 2010 at 19:18:57 +0400
Her E-mail was sent out on Fri, 14 May 2010 at 05:34:22 +0400 (MSD)
MSD mean Moscow Summer Time, +04:00 hours GMT.
X-Mailer: The Bat! (v1.62r) UNREG / CD5BF9353B3B7091
Reply-To: dinalove1977@rambler.ru
X-Priority: 3 (Normal)
Message-ID: <1136748830.20100513191857@rambler.ru>
To: sanfloriani@alice.it
Subject: <spam] Hollo the stranger!!
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----------119EE621096919"
Return-Path: dinalove1977@rambler.ru
Dina's Mail Program (The Bat!)

The Bat! is the most popular FSU mail program, in this case an UNREGistered copy for personal use.

The registered copy allows for mass-mailing and is a favorite tool of spammers.

A MIME (Multipurpose Internet Mail Extensions) Content-Type: multipart/mixed means Dina's E-mail was text plus attachments - a photo:
Image:Dina.jpg
X-OriginalArrivalTime: 14 May 2010 01:34:25.0018 (UTC) FILETIME=<95FBE5A0:01CAF305]
X-Antivirus: AVG for E-mail 9.0.819 [271.1.1/2869]
X-Text-Classification: spam
X-POPFile-Link: http://127.0.0.1:8080/jump_to_message?view=131
My Mail Server received Dina's E-mail 3 seconds later on 14 May 2010 at 01:34:25.0018 (UTC) - UTC or CUT is Coordinated Universal Time.
My anti-virus program (AVG)
and
my anti-spam program (POP File), which judiciously classified Dina's E-mail as spam.

Helpful Tools

To separate an E-mail header into more easily legible chunks:


To resolve an IP address:


Most of the above tools access the regional authority databases through the WHO IS function, which you can do directly yourself:


Another useful tool in this area is Tin Eye (http://www.tineye.com/) where you can submit a photo from your PC or some Internet website, and it will tell you where else on the Internet, to its not infinite knowledge, that photo also appears, be it a dating site, a scammer-listing site or elsewhere.


Conclusions

What have we learned from decoding Dina's E-mail header information?

  • Dina uses a PC, and probably lives, in Yoshkar-Ola, a city as famous for scammers as Lugansk.
  • Her Internet Provider is the local VolgaTelecom, Mari-El branch, giving her a DSL connection with a dynamic IP address (77.40.33.85). Given that private DSL is not as widely available in Russia as in the West, it MAY mean that Dina wrote her E-mail from a PC installed at some public facility (Internet Café, school, office, etc.)
  • Her Mail Server is Moscow's Rambler.ru.
  • Her Mail Program is The Bat!.


The above, and most of all her E-mail text, warrant further investigation.

Google can be a great aid in this - Dina's E-mail address dinalove1977@rambler.ru produces a page on the Zoqy Net blog (http://zoqy.net/?p=1734) written by a French wine lover who also received the SAME letter and photo a week earlier on May 10 through Yahoo Mail.

Therefore, Dina is very likely a scammer with a penchant for European Latins :-))

Further hints on how to spot a scammer can be obtained from RWD's Scammer Score Card (Scam Card: http://www.russianwomendiscussion.com/index.php?pid=34).

Personal tools