Solved

Tracing an IP Address

Posted on 2008-06-19
6
1,007 Views
Last Modified: 2008-10-07
Hi  I have a few IP addresses from the Philippines.  I have traced them using ip-address.com.  

202.69.178.197    This shows as Davo City

202.69.188.253    This also shows as Davo City

Can I be sure that this is where the Email was sent from?   Is there any possibility that a wireless network or other issues would cause this location to be wrong based on the IP address?

Thanks

0
Comment
Question by:service07
  • 2
6 Comments
 
LVL 7

Expert Comment

by:johnny_the_knife
Comment Utility
You can be pretty sure the IP address of the sending mail server in the headers of your email is correct.  Whether the owner of that IP address / Server actually instigated the transmission of the emails is a different matter.

It's possible the mail server is operating in an Open Relay configuration or some software vulnerability, virus etc has been used to send the mail.
0
 

Author Comment

by:service07
Comment Utility
Johnny....are you saying that I can be pretty sure that the IP addresses I listed above are a correct match to Davo City?  I am confident the sender of the Emails did not try to fake the IP address.   The sender of the Emails was NOT supposed to be in that area of the country.  So I want to be fairly sure that the IP address in the Email matches correctly to the Davo City before I begin to ask questions

Please reply back so I can give you your points

Thanks
0
 
LVL 3

Accepted Solution

by:
RTh0037 earned 500 total points
Comment Utility

The IP address info is correct based upon the IP address provided.  As you mentioned, this is in fact provided the IP address was not spoofed or the email was not relayed off another mail server.

IP Info on 202.69.178.197.


address location & IP address info:
IP address [?]: 202.69.178.197
IP address country:  Philippines  
IP address state: Davao City
IP address city: Pampanga
IP address latitude: 7.110000
IP address longitude: 125.648903
ISP of this IP [?]: ComClark Network & Technology Corp.
Organization: Comclark Digitel RAS
Local Time of this IP country: 2008-06-20 13:18



inetnum:      202.69.178.0 - 202.69.178.255
netname:      COMCLARK-DIGITEL-RAS
descr:        Comclark Digitel RAS
country:      PH
admin-c:      MM651-AP
admin-c:      PV32-AP
tech-c:       MM651-AP
tech-c:       PV32-AP
status:       ASSIGNED NON-PORTABLE
mnt-by:       MAINT-PH-COMCLARK
changed:      apnic@comclark.com 20060503
changed:      mcmagat@comclark.com 20060503
source:       APNIC

person:       Michael Magat
nic-hdl:      MM651-AP
e-mail:       mcmagat@comclark.com
address:      Comclark Bldg. Pres. M.A. Roxas Hi-way, CSEZ Clarkfield, Pampanga
phone:        +63-45-599-3777
fax-no:       +63-45-599-3777
country:      PH
changed:      mcmagat@comclark.com 20060425
mnt-by:       MAINT-NEW
source:       APNIC

person:       Philip Michael Vargas
nic-hdl:      PV32-AP
e-mail:       apnic@comclark.com
address:      Comclark Bldg. Pres. M.A. Roxas Hi-way, CSEZ Clarkfield, Pampanga
phone:        +63-45-599-3777
fax-no:       +63-45-599-3777
country:      PH
changed:      apnic@comclark.com 20060123
mnt-by:       MAINT-NEW
source:       APNIC
0
 
LVL 3

Expert Comment

by:RTh0037
Comment Utility
Not sure why points are not divided since he provided very little information
0

Featured Post

Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

Join & Write a Comment

Setting up SSH Cisco We are all told that you should not use Telent for connecting to devices because it is unsecure and all clear text. Much better is to use SSH, but it can seem a bit of a challenge setting it all up and especially in a small n…
This article is in response to a question (http://www.experts-exchange.com/Networking/Network_Management/Network_Analysis/Q_28230497.html) here at Experts Exchange. The Original Poster (OP) requires a utility that will accept a list of IP addresses …
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now