Nirzil | Krary a écrit :
mmc peut tu me dire ce qui t'indique que son IP vient de roumanie? il est possible de le retracer?
|
en console :
whois 86.107.209.179
% This is the RIPE Whois query server #3.
% The objects are in RPSL format.
%
% Rights restricted by copyright.
% See http://www.ripe.net/db/copyright.html
% Note: This output has been filtered.
% To receive output for a database update, use the "-B" flag.
% Information related to '86.107.208.0 - 86.107.215.255'
inetnum: 86.107.208.0 - 86.107.215.255
netname: SC-PROSOFT-COMPUTERS-SRL
descr: SC Prosoft Computers SRL
descr: Sos. Bucuresti Bl. 202/5D, Sc. B, Et.4, Ap.30
descr: Giurgiu Giurgiu 080302
country: ro
admin-c: BCC6-RIPE
tech-c: BCC6-RIPE
status: ASSIGNED PA
remarks: Registered through http://www.jump.ro/ip.html
mnt-by: RO-MNT
mnt-lower: RO-MNT
mnt-routes: PROSOFT-MNT
source: RIPE # Filtered
person: BOGDAN CATALIN COSTEL
address: Prosoft Computers SRL
address: Sos. Bucuresti Bl. 202/5D, Sc. B, Et.4, Ap.30
address: Giurgiu Giurgiu 080302
phone: +40-246-231082
fax-no: +40-246-231082
e-mail: abuse@pscomp.ro
nic-hdl: BCC6-RIPE
mnt-by: PROSOFT-MNT
source: RIPE # Filtered
% Information related to '86.107.208.0/21AS35075'
route: 86.107.208.0/21
descr: SC Prosoft Computers SRL
origin: AS35075
mnt-by: PROSOFT-MNT
source: RIPE # Filtered
% Information related to '86.107.208.0/23AS35075'
route: 86.107.208.0/23
descr: SC Prosoft Computers SRL
origin: AS35075
mnt-by: PROSOFT-MNT
source: RIPE # Filtered |
whois 79.114.235.237
% This is the RIPE Whois query server #3.
% The objects are in RPSL format.
%
% Rights restricted by copyright.
% See http://www.ripe.net/db/copyright.html
% Note: This output has been filtered.
% To receive output for a database update, use the "-B" flag.
% Information related to '79.112.0.0 - 79.119.255.255'
inetnum: 79.112.0.0 - 79.119.255.255
netname: RO-RDS-20070529
org: ORG-RA18-RIPE
descr: RCS & RDS SA
country: RO
admin-c: CN19-RIPE
tech-c: RDS-RIPE
status: ALLOCATED PA
mnt-by: RIPE-NCC-HM-MNT
mnt-lower: AS8708-MNT
mnt-routes: AS8708-MNT
source: RIPE # Filtered
organisation: ORG-RA18-RIPE
org-name: RCS & RDS SA
org-type: LIR
address: Romania Data Systems SA
Ciprian Nica
Forum 2000 Building
71-75 Dr. Staicovici
050557 Bucharest
Romania
phone: +40 21 301 0850
phone: +40 31 400 4243
fax-no: +40 31 400 4207
admin-c: CN19-RIPE
mnt-ref: AS8708-MNT
mnt-ref: RIPE-NCC-HM-MNT
mnt-by: RIPE-NCC-HM-MNT
source: RIPE # Filtered
role: Romania Data Systems NOC
address: 71-75 Dr. Staicovici
address: Bucharest / ROMANIA
phone: +40 21 30 10 888
fax-no: +40 21 30 10 892
abuse-mailbox: abuse@rcs-rds.ro
admin-c: CN19-RIPE
admin-c: GEPU1-RIPE
tech-c: CN19-RIPE
tech-c: GEPU1-RIPE
nic-hdl: RDS-RIPE
mnt-by: AS8708-MNT
remarks: +--------------------------------------------------------------+
remarks: | ABUSE CONTACT: abuse@rcs-rds.ro IN CASE OF HACK ATTACKS, |
remarks: | ILLEGAL ACTIVITY, VIOLATION, SCANS, PROBES, SPAM, ETC. |
remarks: | !! PLEASE DO NOT CONTACT OTHER PERSONS FOR THESE PROBLEMS !! |
remarks: +--------------------------------------------------------------+
source: RIPE # Filtered
person: Ciprian Nica
remarks: Senior IP Engineer
remarks: Romania Data Systems
address: Bucharest, Romania
phone: + 40 31 400 42 43
abuse-mailbox: abuse@rcs-rds.ro
remarks: ------------------------------------------------
remarks: | Please don't send me any abuse complaints. |
remarks: | Use abuse@rcs-rds.ro for that or contact |
remarks: | your service provider or local authorities |
remarks: | !! DO NOT CALL ME REGARDING ABUSE ISSUES !! |
remarks: ------------------------------------------------
nic-hdl: CN19-RIPE
mnt-by: NIMACI-MNT
source: RIPE # Filtered
% Information related to '79.112.0.0/13AS8708'
route: 79.112.0.0/13
descr: RDSNET
origin: AS8708
mnt-by: AS8708-MNT
source: RIPE # Filtered |
whois 200.36.183.18
% Joint Whois - whois.lacnic.net
% This server accepts single ASN, IPv4 or IPv6 queries
% LACNIC resource: whois.lacnic.net
% Copyright LACNIC lacnic.net
% The data below is provided for information purposes
% and to assist persons in obtaining information about or
% related to AS and IP numbers registrations
% By submitting a whois query, you agree to use this data
% only for lawful purposes.
% 2008-09-04 15:04:45 (BRT -03:00)
inetnum: 200.36.183.16/28
status: reassigned
owner: Optel Telecomunicaciones S.A. de C.V.
ownerid: MX-OTSC1-LACNIC
responsible: Ing. Guadalupe Estrada Vazquez
address: Prol Paseo de la Reforma, 1200, Piso 6
address: 05349 - Mexico - DF
country: MX
phone: +52 55 16168300 []
owner-c: GRY
tech-c: GRY
abuse-c: GRY
created: 19980311
changed: 20030624
inetnum-up: 200.36.160/19
inetnum-up: 200.36/16
nic-hdl: GRY
person: Hostmaster Telefonica Empresas Mexico
e-mail: gestrada@TELEFONICAMOVILES.COM.MX
address: Prol Paseo de la Reforma, 1200, address: 05349 - Mexico - DF
country: MX
phone: +52 55 16168300 []
created: 20030108
changed: 20070130 |
etc, etc...
Il est surement arrivé jusqu'à ton serveur avec un petit script nmap qui scanne des plages d'IP les unes après les autres jusqu'à ce qu'il en rencontre une qui lui répond et hop, tentative d'intrusion directe derrière Message édité par Nirzil le 04-09-2008 à 20:17:27
|