User Posted Information Regarding IP's of Other Users

The 2.0.x discussion forum has been locked; this will remain read-only. The 3.0.x discussion forum has been renamed phpBB Discussion.
Locked
Steve E
Registered User
Posts: 2
Joined: Wed May 21, 2008 11:47 pm

User Posted Information Regarding IP's of Other Users

Post by Steve E » Wed May 21, 2008 11:56 pm

I'm helping out a friend (forum garbage man, essentially) and have administrator privileges. Currently we're using 2.0.23, but the owner of the forum will be making a move to 3.0 sometime later this year.

One of our users mentioned multiple IP information regarding other users. As far as I'm aware, only the owner, myself, and another person have access to the IP's. Although they didn't list the actual IP addresses, they made a comment that I know to likely be true based on their information.

They also did some research on another user, making mention that Rx records are on file and public - that $29.95 can buy all sorts of information. So this person is doing this maliciously, and may be using people with more knowledge in how to get this information than we have to keep it from happening.

How is it that a user can gain IP address information such as this? Is it rather easy and I haven't figured it out yet, or did they likely employ someone with some hacking abilities to look beyond the page itself to get the info?

Thanks.

SE

User avatar
Dog Cow
Registered User
Posts: 2494
Joined: Fri Jan 28, 2005 12:14 am
Contact:

Re: User Posted Information Regarding IP's of Other Users

Post by Dog Cow » Fri May 23, 2008 4:47 pm

There is more than one way to get information about a user. Let's imagine this scenario:

A person named Bobby uses that same username across multiple forums, including yours. A user named Manny has his own forum which he is the administrator of. Manny is a regular member of your forum, and Bobby is a member of Manny's forum.

Because Bobby is a member at Manny's forum as well as yours, Manny the administrator can view his IP addresses. Manny of course can't view Bobby's IP addresses at your forums, but he can still be reasonably confident with his information. He can then take this information over to your forums, where he is not an administrator, and post it publicly and/or do other unpleasant things.
Moof!
Mac GUI Vault: Retro Apple II & Macintosh computing archive.
Inside Allerton bookMac GUIMac 512K Blog

User avatar
KevC
Support Team Member
Support Team Member
Posts: 69366
Joined: Fri Jun 04, 2004 10:44 am
Location: Oxford, UK
Contact:

Re: User Posted Information Regarding IP's of Other Users

Post by KevC » Fri May 23, 2008 4:50 pm

It's not unusual for a user to have more than one IP address. I have over 1500 for my posts on here.

There also isn't a lot you can do with an IP address anyway.
-:|:- Support Request Template -:|:-
Image
Cheap UK Hosting
"In the land of the blind the little green bloke with no pupils is king - init!"

Steve E
Registered User
Posts: 2
Joined: Wed May 21, 2008 11:47 pm

Re: User Posted Information Regarding IP's of Other Users

Post by Steve E » Fri May 23, 2008 6:44 pm

Thanks Dog Cow and Kevin,

I understand your scenario, although it's unlikely that it applies in this situation. Knowing some background on the situation (which included several other attacks) what they are saying is true (multiple posters from the same IP). I do know that several people can share an IP, etc... but I don't understand how they were able to see the IP to know whom it was coming from.

So the accusation that X number of 'users' all posted from the same IP isn't really the issue, not is how many IP's they've used - but that they knew X number of 'users' were posting from the same IP is what is confusing. And they got the number correct.

The way the board is configured, the IP's aren't visible, within the thread. But by clicking the IP link, I can see the IP as well as anyone who's posted from it and any others used by that person (relating to Kevin's comment). It seems like this person may be accessing this information also.

User avatar
KevC
Support Team Member
Support Team Member
Posts: 69366
Joined: Fri Jun 04, 2004 10:44 am
Location: Oxford, UK
Contact:

Re: User Posted Information Regarding IP's of Other Users

Post by KevC » Fri May 23, 2008 7:24 pm

Get the starfox admin toolkit in my sig below.
That will allow you to see if anyone else has a mod or admin account that shouldn't.

Also as DC says, it's feasible they know the account names from another board and knew the information already.
-:|:- Support Request Template -:|:-
Image
Cheap UK Hosting
"In the land of the blind the little green bloke with no pupils is king - init!"

ckwalsh
Former Team Member
Posts: 1837
Joined: Wed Mar 15, 2006 1:50 am
Location: Seattle, USA
Name: Cullen Walsh
Contact:

Re: User Posted Information Regarding IP's of Other Users

Post by ckwalsh » Sat May 24, 2008 1:07 am

This is a stab in the dark (and probably wrong), but does that user have an image in their signature?

Theoretically (I'm not sure why someone would want to), it is possible for someone to use their own server and an image to track how many different users have viewed the image, like a counter, but not displaying the count publicly. From this information, they would not be able to see who the users are however.

You should take all steps to try figure out how they are doing this, but it may just be someone trying to scare you.
Where to post what | Forum Rules | The Dos and Don'ts of General Discussion
In Seattle and want to meet, chat, or have a coffee? Drop me a PM.

User avatar
3Di
Former Team Member
Posts: 14245
Joined: Mon Apr 04, 2005 11:09 pm
Location: Milan (IT) Frankfurt (DE)
Name: Marco
Contact:

Re: User Posted Information Regarding IP's of Other Users

Post by 3Di » Sat May 24, 2008 1:35 am

Ditto. :geek:

It is a film I've already saw. :)
Please PM me only to request paid works. Thx.
Want to compensate me for my interest? Donate
My development's activity º PhpStorm's proud user
Extensions, Scripts, MOD porting, Update/Upgrades
👨‍🏫 | Take a tour to | The Studio | 👨‍🏫

User avatar
Dog Cow
Registered User
Posts: 2494
Joined: Fri Jan 28, 2005 12:14 am
Contact:

Re: User Posted Information Regarding IP's of Other Users

Post by Dog Cow » Sat May 24, 2008 4:49 pm

Steve E wrote:Thanks Dog Cow and Kevin,

I understand your scenario, although it's unlikely that it applies in this situation. Knowing some background on the situation (which included several other attacks) what they are saying is true (multiple posters from the same IP). I do know that several people can share an IP, etc... but I don't understand how they were able to see the IP to know whom it was coming from.

So the accusation that X number of 'users' all posted from the same IP isn't really the issue, not is how many IP's they've used - but that they knew X number of 'users' were posting from the same IP is what is confusing. And they got the number correct.

The way the board is configured, the IP's aren't visible, within the thread. But by clicking the IP link, I can see the IP as well as anyone who's posted from it and any others used by that person (relating to Kevin's comment). It seems like this person may be accessing this information also.
Well, you have two options:

1.) Run some tests on him: ask this guy to confirm some information that you know. For example, since he guessed the number of different IPs, ask him to tell you what they are.

Play with his mind. Tell him there's another, new IP address that is in use and ask him to tell you what it is. Or, tell him he's got some wrong IPs, or the wrong number of them. See what his reaction is.

The point here is to get the most information from him, while giving him the least information.

2.) It could be possible this guy has moderator permissions and really is clicking that IP button on your forums. Check carefully his user-assigned permissions, then check if he's in any groups with moderator permissions. I had acase years ago where some really old member got assigned to be a moderator by mistake. I fixed it, of course, but it still can happen.
Moof!
Mac GUI Vault: Retro Apple II & Macintosh computing archive.
Inside Allerton bookMac GUIMac 512K Blog

Locked

Return to “2.0.x Discussion”