Forum Moderators: open

Message Too Old, No Replies

A CSS and JS sniffer?

Can't track this one

         

Macguru

4:26 pm on Sep 7, 2001 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I get visits from 193.251.152.238 it grabed only external CSS and JS on one of my sites. I dont have access to log files on this host, can't get user agent. I get no match for the host.

Any one can track it?

Key_Master

4:44 pm on Sep 7, 2001 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



inetnum: 193.251.152.0 - 193.251.152.255
netname: EEPADNET
descr: Etablissement d'Enseignement Professionnel A Distance
descr: Tele-Learning, Internet Service Provider in Algeria
country: DZ
admin-c: GF2814-RIPE
tech-c: MT10010-RIPE
remarks: for hacking, spamming or security problems send mail to
remarks: abuse@djazair-connect.com
status: ASSIGNED PA
notify: gestionip.ft@francetelecom.com
mnt-by: FT-BRX
changed: gestionip.ft@francetelecom.fr 19991228
changed: gestionip.ft@francetelecom.fr 20001010
changed: gestionip.ft@francetelecom.com 20010417
changed: gestionip.ft@francetelecom.com 20010614
source: RIPE

route: 193.251.128.0/19
descr: France Telecom
descr: OPENTRANSIT
origin: AS5511
mnt-by: FT-BRX
changed: gestionip.ft@francetelecom.fr 20001017
source: RIPE

person: GOUASMIA Fadi
address: EEPAD
address: 11 Rue des 3 freres Bouaddou
address: Bir Mourad Rais - Alger
phone: +213 21 44 99 99
fax-no: +213 21 44 90 42
e-mail: fadi.gouasmia@djazair-connect.com
nic-hdl: GF2814-RIPE
notify: gestionip.ft@francetelecom.com
mnt-by: FT-BRX
changed: gestionip.ft@francetelecom.com 20010614
source: RIPE

person: Mohamed TIMOUNT
address: EEPAD-Djazair-connect
address: Bir Mourad Rais
address: Residence Ennadjah
address: Rue des 3 freres bouaddou
address: Alger
phone: +213 21 44 99 99
fax-no: +213 21 44 90 43
e-mail: timount_m@djazair-connect.com
nic-hdl: MT10010-RIPE
notify: gestionip.ft@francetelecom.com
mnt-by: FT-BRX
changed: gestionip.ft@francetelecom.com 20010417
source: RIPE

mivox

4:46 pm on Sep 7, 2001 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Well, the RIPE whois search [ripe.net] pointed to an Algerian ISP...

descr: Etablissement d'Enseignement Professionnel A Distance
descr: Tele-Learning, Internet Service Provider in Algeria

The contact emails were all from either francetelecom.fr, francetelecom.com or djazair-connect.com

That's about as fancy as *my* investigative skills get...

Macguru

4:50 pm on Sep 7, 2001 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Thank you Key_Master and mivox,

My tracking sources just rippened. :)

mivox

4:55 pm on Sep 7, 2001 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Apparently, Key_Master can cut and paste faster than I type.... ;)

My personal IP search starting point is always the ARIN whois search: [arin.net...]

If the IP in question isn't assigned by ARIN, their search results will give you a link to either RIPE whois (if it's a european IP assignment) or APNIC (if it's an Asian IP) in their search results.