Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other firewalls
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 7th, 2008, 12:29 AM
jrx10 jrx10 is offline
Regular Poster
 
Join Date: Jan 2007
Posts: 85
Default ? for you FW pros. Track down IP reassignments

Every so often I get an strange inbound or outbond that I want to check out. A lot, but not all, of the info about an IP just shows the server and doesn't give me anything about the reassignment. An example is (and this is only an example), is the search for ImageShack IP address. It brings up "Performance Systems Intl" Washington, D.C. NetName: PSINETA. It also says "Comment: Reassignment information for this block can be found at
Comment: rwhois.cogentco.com 4321". In this particular case, I know, or think it's an ImageShack address, but you couldn't tell it by looking up the IP. Is there any way to look up these reassignments within a listed server to actually find out where this outbound is going/inbound coming from? PSI doesn't tell me jack, but is there any way to read through the BS and get to these reassignments, in this particular example...ImShack? thx
  #2  
Old May 9th, 2008, 12:18 AM
jrx10 jrx10 is offline
Regular Poster
 
Join Date: Jan 2007
Posts: 85
Default Re: ? for you FW pros. Track down IP reassignments

Bump. Anyone?
Is this a closely-guarded 'net secret or just not possible/not available to general web surfers to look beyond these vague ARIN entries you get from looking up/tracking down a strange logged inbound/outbound IP? Now-a-days with everyone preaching 'net security, it would seem like there would be a mandatory & constantly updated encyclopedia of these 'net server website IP reassignments, somewhere?
Another example is WSF.....you get Reliance Globalcom Services, Inc RGS-BLK7 (NET-65-175-0-0-1)
65.175.0.0 - 65.175.63.255
Freeze Frame Graphics YIPS-FREEZE-S01217006 (NET-65-175-38-0-1)
65.175.38.0 - 65.175.38.255
and absolutely nothing directly relating to WSF.
  #3  
Old May 9th, 2008, 01:27 AM
Stem Stem is offline
Firewall Expert
 
Join Date: Oct 2005
Location: UK
Posts: 4,948
Default Re: ? for you FW pros. Track down IP reassignments

Rather than using a Whois which will normally only show the block. Use a reverse DNS, some info http://en.wikipedia.org/wiki/Reverse_DNS_lookup

Lookups can be made (as example) here:- http://www.dnsstuff.com/


- Stem
 

Wilders Security Forums > Security Products > other firewalls « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:51 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums