Click to See Complete Forum and Search --> : Reverse DNS Lookup


Dane Olson
07-23-2002, 09:45 PM
I have set up a firewall that seems to be doing the trick, after I got hacked into a few weeks ago. Since then I have been checking my logs daily. I setup RH 7.3 plus patches to latest rev's. In my logs I see an anormous list of a specific IP address being denied access. The address is 12.242.20.34 on port 67. on some ocations this address tried to access my firewall about every 4 seconds. I would love to shut this person down but I do not have any knoledge of how to identify who is using or owns this address. Can any one tell me how to get additional information on this IP address so that I might be able to report this activity to the owner and/or authorities?

Bokkenka
07-23-2002, 11:23 PM
You can go to the American Registry for Internet Numbers (www.arin.net) and click the tools button to get to the whois lookup. Just enter the number that, and it will tell you who it's registered to.

X_console
07-24-2002, 11:42 AM
You can also use tools such as dig, host and whois on your Linux box to do this for you.