richrumble is right, he cannot launch an attack remotely without an IP, he can however spoof IP traffic and direct it to your site. The only problem with that from a Hackers perspective is that this only allows him to DOS you. He will not be able to retieve any information or he/she will not be able to gain access.
Do you mean that you do not know his real IP? Your ISP can still track his traffic even if he is spoofing the traffic. If this is the case you may need to engage your ISP to assist in tracking him down.
Good IDS/IDP software, Snort, www.snort.org.
harbor235 ;}
Main Topics
Browse All Topics





by: richrumblePosted on 2006-09-22 at 06:26:02ID: 17577326
Packets can't be routed with out an ip, so it's there. Windows event log might not be able to tell you what it is, but a netstat -an or a firewall can and will. When the attack is going on, a netstat -an will tell you the ips of those connected, a firewall such as zonealarm can log the ip no problem. You can even install wireshark aka ethereal to sniff the packets and get the ip address from that.
-rich