Forum Moderators: phranque
A search of the IP address came up a complete blank. My most reliable IP search site came up a complete and total blank.
A Google search of that IP address showed it associated with some sort of uasge stats.
So is there a company that has a completely untraceable IP address that can do what I described above for the purpose of gathering usage stats?
Would it help if I put the IP address here. I didn't out of consideration for whatever privacy rights still can be observed on our fine Net, but if it'll help in any way I suppose I could do so. I have noticed suspicious IP addresses posted in other threads.
Any advice?
I often open several browser windows in a forum, **especially** if it's running slow. If the authentication holds for each window, you could see how this would show several entries in your logs and may not be any real suspicious activitity. It may also indicate that this user has nothing to do with your problem.
I wouldn't post the IP (see TOS.)
Powered by phpBB 2.0.8 © 2001 phpBB Group
phpBB port v2.1 based on Tom Nitzschner's phpbb2.0.6 upgraded to phpBB 2.0.4 standalone was developed and tested by:
ArtificialIntel, ChatServ, mikem, sixonetonoffun and Paul Laudanski (aka Zhen-Xjell).
Version 2.1 by Nuke Cops © 2003 [nukecops.com...]
I'm doing this because I don't think a guest, or even a member can open multiple windows. But check that info up there and if I'm wrong, well, it wouldn't be the first time. More like the zillionth time.
Now, I see you're a senior member, which I gather to mean very wize in all things of this fine site and the Net in general, so would you reckon it's okay to post the suspect IP address here.
By the way, the sluggishness isn't what I'm concerned about. That was just to explain one aspect of this mystery. In fact, the site gets sluggish off and on and at preent I'm not too concerned about that. I just don't feel comfortable with the fact that one IP address was able to be in all places at once. I'm going to see if I can copy/paste the info from that screen capture image.
[edited by: jimji at 6:26 pm (utc) on Nov. 11, 2005]
Now I transcribed the info from the screen capture image. I was wrong, I copied 14 entries and there was at least one more maybe two.
Dates are all Nov. 11, 2005 – Times are 11:23 am X 2, 11:22 am X 4, 11:21 am X 3, 11:20 am X 4, 11:19 am X one that I copied and maybe one or two more.
Locations: (in the same order as times are listed) Forum Index X 2; Viewing Private Message X 1; Forum Index X 1; Benefits X 1; Posting a message X 2; Benefits X 2; Forum Index X 1; Benefits X 1; Posting a message X 2.
And as I wrote there seems to be more, but I didn’t do the screen capture correctly to get everything. And per instructions I’m not posting the IP addresss.
So that’s 14 listings that I captured for a guest with the same IP address. How can that be?
Now, I have no members with a User ID "guest". I banned that name. So how could a guest be viewing a private message.
Oh yes, thank you everyone for the help.
As for one IP having many connections being allowed, that seems reasonable. If your software only allowed one connection per IP it would cause problems with schools or business's where hundreds of people run through a proxy.
(how in the world do you spell business's correctly?)
phpBB counts anyone viewing your pages who is not logged in as "guest". While it is possible for 14 different unregistered and/or logged off users to surf your site from the same IP address at the same time, it is not probable. My guess is it is a bot, probably malicious if the lookup yields no results. If it is accessing your site using multiple connections it very well could be slowing down your server. Take a look at this post on ways to identify and ban bad bots:
[webmasterworld.com...]
Here is what ARIN WHOIS says,
OrgName: Japan Network Information Center
OrgID: JNIC
Address: Kokusai-kougyou-Kanda Bldg 6F
Address: 2-3-4 Uchikanda
City: Chiyoda-ku
StateProv: Tokyo
PostalCode: 101-0047
Country: JPNetRange: 133.0.0.0 - 133.255.255.255
CIDR: 133.0.0.0/8
NetName: JAPAN-INET
NetHandle: NET-133-0-0-0-1
Parent:
NetType: Direct Allocation
NameServer: A.DNS.JP
NameServer: B.DNS.JP
NameServer: D.DNS.JP
NameServer: E.DNS.JP
NameServer: F.DNS.JP
Comment: Japan Network Information Center(JPNIC) is an
Comment: National internet registry of Japan. Please search
Comment: whois.nic.ad.jp for more information about this range.
Comment: % whois -h whois.nic.ad.jp ***.***.***.***/e
RegDate:
Updated: 2005-03-22RTechHandle: JN-ORG-ARIN
RTechName: Japan Network Information Center
RTechPhone: +81-3-5297-2311
RTechEmail: hostmaster@nic.ad.jpOrgTechHandle: JN-ORG-ARIN
OrgTechName: Japan Network Information Center
OrgTechPhone: +81-3-5297-2311
OrgTechEmail: hostmaster@nic.ad.jp# ARIN WHOIS database, last updated 2005-11-10 19:10
# Enter? for additional hints on searching ARIN's WHOIS database.
It says to search whois.nic.ad.jp which gives this result,
Network Information:
a. [Network Number] 133.9.0.0/16
b. [Network Name] WASEDA-NET
g. [Organization] WASEDA University
m. [Administrative Contact] SH4668JP
n. [Technical Contact] AI016JP
n. [Technical Contact] HW1297JP
n. [Technical Contact] KO5486JP
n. [Technical Contact] TY6273JP
p. [Nameserver] ns.cfi.waseda.ac.jp
p. [Nameserver] ns2.cfi.waseda.ac.jp
[Assigned Date] 1989/05/01
[Return Date]
[Last Update] 2005/08/22 10:52:26(JST)
Less Specific Info.
----------
No match!More Specific Info.
----------
No match!
and Administrative Contact gives this information,
Contact Information:c. [Last, First] Hirasawa, Shigeichi
d. hira@waseda.jp
g. [Organization]WASEDA University
l. [Division] Media Network Center
n. [Title] Dean and Directordomain@list.waseda.jp
2005/02/16 15:17:04(JST)
I'm seems that your IP is coming from the WASEDA University in Japan - [waseda.jp...]
I've often got many many different pages of a phpBB forum open in Firefox, Mozilla, newer Netscape, or Opera browsers. I could conceivably open multiple reply-to-message pages, compose replies to all of them, and then post them in quick succession. What user-agent is your visitor using?
Jim
Again, I sure appreciate the help.
So my question is how that is possible? What would be the mechanics of that? A guest obviously has no private messages, so why would that be showing?
But when you ask about "user-agent" are you referring to info in twist's message? I'm not quit sure I understand "user-agent"?