Announcement

Collapse
No announcement yet.

finding out the MAC address through IP

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • finding out the MAC address through IP

    I have an issue with someone that keeps trying to hack me. I know their IP, it keeps comming up in Apache's logs all the time. But my router doesnt have IP block, only MAC address block. So how would I find some1 elses MAC address through use of IP.
    BTW i tried pinging the IP, with no luck, Request timed out - error. I was thinking of a sniffer, but that would just give me the address of the router, rite?
    any help here would be appricieated.[/list]

  • #2
    i don't know about the MAC address, but you can at least trace the IP back to the ISP, then file a complaint with them. try using the tracert <IP> command from the command line

    EDIT: you could also try a whois lookup at arin.net. while it wont give you a MAC address it will give you some detailed information about the provider

    Comment


    • #3
      CCGetMAC can be used to get/find/get/lookup MAC address and Wake On LAN. It is a handy tool for finding MAC address and computer name from IP address.

      ^ that tool will let you find MAC from IP but i don't think you will be successful untill you actually connect to the machine by way of ping or something like that but you can still try. since this person is sending "time out" while pinging then looks like he/she is running a firewall.
      Your Trusted Design and Construction Building Consultant | DCCS.TM

      ^ that is another site similar to what minibubba suggested.
      Latest Microsoft Security Updates.
      Last Updated:
      10th MARCH


      If you are a security freak: Use Microsoft Baseline Security Analyzer (NT/2000/XP/2003)
      ======================
      icq : 203189004
      jabber : [email protected]
      =======================
      Linux user since: April 24, 2003 312478
      yabaa dabaa doo...
      Customized for 1024x768

      Comment


      • #4
        Originally posted by kane2g
        But my router doesnt have IP block, only MAC address block.[/list]
        Your router can only block MAC addresses that are connected Through it.

        Comment


        • #5
          yeah, i figured that out :oops:
          but as I am thinking of using something like www.smoothwall.org for my fireewall, rather than the router.
          guess the banning IPs will have to do.

          Comment


          • #6
            What do you mean, "will have to do" ? Hehe.... It's a flawless system.... 8)

            Comment


            • #7
              Well, just checking the logs everyday and making sure someone didnt just get a fresh IP. Banning a MAC would make it a lot easier. But oh-well. Tis a job of a admin I guess :wink:

              Comment


              • #8
                hmm: if you can make a connection of some sort to the machine you should be able to query the physical address [MAC address] with the ARP command like so.

                ARP- A a.b.c.d

                where a.b.c.d is the ip address..

                Comment


                • #9
                  I just thought of something. How are they trying to hack you?

                  Comment


                  • #10
                    this is apache's access log


                    24.17.227.36 - - [19/Mar/2004:02:25:42 -0800] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 489
                    24.17.227.36 - - [19/Mar/2004:02:25:42 -0800] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 489
                    24.17.227.36 - - [19/Mar/2004:02:25:42 -0800] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 489
                    24.17.227.36 - - [19/Mar/2004:02:25:42 -0800] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 489
                    24.17.227.36 - - [19/Mar/2004:02:25:43 -0800] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 489
                    24.17.227.36 - - [19/Mar/2004:02:25:43 -0800] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 489
                    24.17.227.36 - - [19/Mar/2004:02:25:43 -0800] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 489
                    24.17.227.36 - - [19/Mar/2004:02:25:44 -0800] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 489
                    24.17.227.36 - - [19/Mar/2004:02:25:44 -0800] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 489
                    24.17.227.36 - - [19/Mar/2004:02:25:45 -0800] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 489
                    24.17.227.36 - - [19/Mar/2004:02:25:45 -0800] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 489
                    24.17.227.36 - - [19/Mar/2004:02:25:45 -0800] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 489
                    24.17.227.36 - - [19/Mar/2004:02:25:45 -0800] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 296
                    24.17.227.36 - - [19/Mar/2004:02:25:45 -0800] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 296
                    24.17.227.36 - - [19/Mar/2004:02:25:45 -0800] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 489
                    24.17.227.36 - - [19/Mar/2004:02:25:46 -0800] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 489



                    here is error log

                    [Thu Mar 18 23:57:44 2004] [error] [client 67.167.106.111] File does not exist: C:/Apache2/htdocs/default.ida
                    [Fri Mar 19 02:25:42 2004] [error] [client 24.17.227.36] File does not exist: C:/Apache2/htdocs/scripts
                    [Fri Mar 19 02:25:42 2004] [error] [client 24.17.227.36] File does not exist: C:/Apache2/htdocs/MSADC
                    [Fri Mar 19 02:25:42 2004] [error] [client 24.17.227.36] File does not exist: C:/Apache2/htdocs/c
                    [Fri Mar 19 02:25:42 2004] [error] [client 24.17.227.36] File does not exist: C:/Apache2/htdocs/d
                    [Fri Mar 19 02:25:43 2004] [error] [client 24.17.227.36] File does not exist: C:/Apache2/htdocs/scripts
                    [Fri Mar 19 02:25:43 2004] [error] [client 24.17.227.36] File does not exist: C:/Apache2/htdocs/_vti_bin
                    [Fri Mar 19 02:25:43 2004] [error] [client 24.17.227.36] File does not exist: C:/Apache2/htdocs/_mem_bin
                    [Fri Mar 19 02:25:44 2004] [error] [client 24.17.227.36] File does not exist: C:/Apache2/htdocs/msadc
                    [Fri Mar 19 02:25:44 2004] [error] [client 24.17.227.36] File does not exist: C:/Apache2/htdocs/scripts
                    [Fri Mar 19 02:25:45 2004] [error] [client 24.17.227.36] File does not exist: C:/Apache2/htdocs/scripts
                    [Fri Mar 19 02:25:45 2004] [error] [client 24.17.227.36] File does not exist: C:/Apache2/htdocs/scripts
                    [Fri Mar 19 02:25:45 2004] [error] [client 24.17.227.36] File does not exist: C:/Apache2/htdocs/scripts
                    [Fri Mar 19 02:25:46 2004] [error] [client 24.17.227.36] File does not exist: C:/Apache2/htdocs/scripts
                    [Fri Mar 19 05:27:42 2004] [error] [client 67.167.106.111] File does not exist: C:/Apache2/htdocs/default.ida

                    i get simillar errors from following IPs.
                    67.163.226.215
                    67.167.106.39
                    67.167.115.119
                    67.168.94.16
                    67.113.192.182
                    67.166.183.64
                    129.25.34.226
                    67.163.240.32
                    24.17.227.36

                    Whois tells me that most of them 67.x.x.x are Comcast :(

                    Comment


                    • #11
                      I think you'll find most of them are just viruses trying to spread. Blocking or not, you'll still get the traffic. As it's not doing anything, and there's not a lot you can do about it, just let it go.

                      What ports are you forwarding on your router? Just web/ftp, or did you do something silly like put your webserver in the DMZ?

                      Comment


                      • #12
                        just forwarding the 80 port,
                        Decided against DMZ with your (i think) advise :D

                        Comment

                        Working...
                        X