Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Help please, how do I find out where a message came from (ISP?)

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » DU Groups » Computers & Internet » Computer Help and Support Group Donate to DU
 
uppityperson Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Dec-07-05 09:07 PM
Original message
Help please, how do I find out where a message came from (ISP?)
Help please. I am trying to track down the originating computer of a message as the person is also a stalker. I can get "message source" but this gives a bunch of numbers, so how do I tell which is the originating place? Here's one example, with personal stuff deleted(me=me, myprovider is my provider, nasty is sender, * is senders provider, my mail gets sent through postini to viruscheck before coming on to me). Thank you so much.

rom - Wed Dec 07 10:01:20 2005
X-Account-Key: account2
X-UIDL: d]E"!Lp-!!"TB"!HoL"!
X-Mozilla-Status: 0011
X-Mozilla-Status2: 00000000
Return-path: <nasty@*.net>
Envelope-to: me@myprovider.com
Delivery-date: Wed, 07 Dec 2005 00:52:59 -0800
Received: from pop3.myprovider.com (<208.200.248.2> helo=myprovider3.myprovider.com)
by myprovider3.myprovider.com with esmtp (Exim 4.43)
id 1Ejv2p-0005px-H7
for me@myprovider.com; Wed, 07 Dec 2005 00:52:59 -0800
Received: from exprod6mx163.postini.com (<64.18.1.163> helo=psmtp.com)
by myprovider3.myprovider.com with smtp (Exim 4.43)
id 1Ejv2p-0005pi-3z
for me@myprovider.com; Wed, 07 Dec 2005 00:52:59 -0800
Received: from source (<209.165.130.12>) by exprod6mx163.postini.com (<64.18.5.10>) with SMTP;
Wed, 07 Dec 2005 00:52:58 PST
Received: from <10.0.1.2> (<65.74.32.217>)
by msgmmp-2.*.net (Sun Java System Messaging Server 6.2-3.03 (built Jun 27
2005)) with ESMTP id <0IR400128E0062I0@msgmmp-2.*.net> for
me@myprovider.com; Tue, 06 Dec 2005 23:52:53 -0900 (AKST)
Date: Tue, 06 Dec 2005 23:52:51 -0900
From: Nasty <nasty@*.net>
Subject: Re:
In-reply-to: <4395C6EE.3090305@olypen.com>
To: <me@myprovider.com>
Message-id: <115A5D39-E1C7-499C-ACB6-65E561B0C7B6@gci.net>
MIME-version: 1.0
X-Mailer: Apple Mail (2.746.2)
Content-type: text/plain; charset=US-ASCII; delsp=yes; format=flowed
Content-transfer-encoding: 7BIT
References: <E744FC2C-A37C-4307-9657-1D5DA5230188@gci.net>
<4395C6EE.3090305@myprovider.com>
X-pstn-levels: (S:99.90000/99.90000 R:95.9108 P:95.9108 M:96.8122 C:99.7951 )
X-pstn-settings: 4 (1.5000:1.5000) s gt3 gt2 gt1 r p m c
X-pstn-addresses: from <nasty@*.net> forward (user good) <3591/147>
X-OLYPEN-SPF: pass
X-UIDL: d]E"!Lp-!!"TB"!HoL"!
Printer Friendly | Permalink |  | Top
bemildred Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Dec-07-05 09:40 PM
Response to Original message
1. Comments:
10.0.1.2 - is a reserved domain (for private networks), doesn't tell you anything.
Reverse DNS on the next three (65.74.32.217,64.18.5.10,209.165.130.12) gives:

217.32.74.65.in-addr.arpa name = 217-32-74-65.gci.net.
12.130.165.209.in-addr.arpa name = msgmmp-2.gci.net.
10.5.18.64.in-addr.arpa name = *.mail5.psmtp.com.

So, it seems to be coming from someplace named "gci.net", which is here:

http://gci.net/

You might consider contacting them about Mr. Nasty, but be polite, this is speculative.
Printer Friendly | Permalink |  | Top
 
uppityperson Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Dec-08-05 02:06 AM
Response to Reply #1
2. Thanks. gci is the place, wondering if we could track it down further
or have to check with gci. I think it is coming from not a dialup, but something that is continuously on (DSL, satellite, some such) so I was hoping someone could help me figure out the more specific #'s, or perhaps we might end up blocking all gci from our website.. Thank you for the input and we may just contact gci.
Printer Friendly | Permalink |  | Top
 
bemildred Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Dec-08-05 07:17 AM
Response to Reply #2
3. Not that I know of.
You would have to talk to GCI, since they control things from there on in.
It should be easy to set up an IP filter (in a firewall, for gci) or a mail filter for Mr. Nasty.
You can lawyer GCI about Mr. Nasty too, but that takes work and money.
Of course there are other things as well, but we won't go into that, we could get in trouble ourselves.
Printer Friendly | Permalink |  | Top
 
uppityperson Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Dec-08-05 12:49 PM
Response to Reply #3
4. Thank you very much, don't want to get into trouble, avoid it
peace
Printer Friendly | Permalink |  | Top
 
alfredo Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Dec-08-05 01:01 PM
Response to Reply #3
5. If gci doesn't respond appropriately, send all correspondence
to your ISP to let them know gci refuses to police its own customers.

I would first filter out this person's address. Some mail clients will let you bounce the mail. Mail.app in OSX allows you to. I don't know about the others.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Sun May 05th 2024, 03:15 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » DU Groups » Computers & Internet » Computer Help and Support Group Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC