6 Feb 2018 at 15:50 #1 DaZzZa DaZzZa Soldato Joined 2 Dec 2002 Posts 2,647 Location Peterlee As title have a few malwarebytes alerts from a user but only have an IP address of the site? Cheers chaps
As title have a few malwarebytes alerts from a user but only have an IP address of the site? Cheers chaps
6 Feb 2018 at 15:56 #2 Steveocee Steveocee Soldato Joined 5 Nov 2011 Posts 5,578 Location Derbyshire Packet inspection through Wireshark? Most website will be on shared hosting so an IP won't be of much help.
Packet inspection through Wireshark? Most website will be on shared hosting so an IP won't be of much help.
6 Feb 2018 at 16:04 #3 DaZzZa DaZzZa Soldato OP Joined 2 Dec 2002 Posts 2,647 Location Peterlee Managed to pull them as ****book someone's getting bored with their marriage.....
7 Feb 2018 at 09:26 #4 RoyMi6 RoyMi6 Soldato Joined 9 Mar 2010 Posts 2,865 A reverse IP lookup is what you want (or rather, will do what you're asking) http://www.viewdns.info/reverseip/ Of course, Steveocee is right that the results you'll get will simply list every site that's hosted rather than just one though. Packet inspection is really the only route. Or... send the user the list and says "Oi! Which one of these dodgy sites are you visiting?" OR.. you could visit each one in turn and monitor your own traffic.
A reverse IP lookup is what you want (or rather, will do what you're asking) http://www.viewdns.info/reverseip/ Of course, Steveocee is right that the results you'll get will simply list every site that's hosted rather than just one though. Packet inspection is really the only route. Or... send the user the list and says "Oi! Which one of these dodgy sites are you visiting?" OR.. you could visit each one in turn and monitor your own traffic.
7 Feb 2018 at 14:01 #5 DaZzZa DaZzZa Soldato OP Joined 2 Dec 2002 Posts 2,647 Location Peterlee Cheers chaps seems to be going on to sites to watch fuzball and popups are setting off malwarebytes
7 Feb 2018 at 14:24 #6 Caged Caged Man of Honour Joined 18 Oct 2002 Posts 26,669 Another thing you can do is connect to HTTPS and see what names are in the certificate
7 Feb 2018 at 15:20 #7 Sp00n Sp00n Soldato Joined 18 Oct 2002 Posts 18,296 Location Brighton Caged said: Another thing you can do is connect to HTTPS and see what names are in the certificate Click to expand... Unless they're only using SNI.
Caged said: Another thing you can do is connect to HTTPS and see what names are in the certificate Click to expand... Unless they're only using SNI.
7 Feb 2018 at 18:28 #8 DaZzZa DaZzZa Soldato OP Joined 2 Dec 2002 Posts 2,647 Location Peterlee Have that part sorted just trying to locate or contact a rogue computer IP on the network now or block it all together on a draytek 2860
Have that part sorted just trying to locate or contact a rogue computer IP on the network now or block it all together on a draytek 2860
7 Feb 2018 at 18:31 #9 Delta3D Delta3D Associate Joined 16 Apr 2014 Posts 1,300 Location North East, UK Cmd Prompt -> ping -a *ip*
7 Feb 2018 at 18:46 #10 On Holiday On Holiday Soldato Joined 29 Dec 2009 Posts 7,280 Delta3D said: Cmd Prompt -> ping -a *ip* Click to expand... That's just the rDNS record for the IP address so of very little use in this case. As previously mentioned; http://www.viewdns.info/reverseip/ is the best method to view domains hosted on an IP. Going on to sites to watch football will no doubt be filled with ads. Just disabled the notifications from Malwarebytes, it's doing it's job. Wouldn't worry about it at all.
Delta3D said: Cmd Prompt -> ping -a *ip* Click to expand... That's just the rDNS record for the IP address so of very little use in this case. As previously mentioned; http://www.viewdns.info/reverseip/ is the best method to view domains hosted on an IP. Going on to sites to watch football will no doubt be filled with ads. Just disabled the notifications from Malwarebytes, it's doing it's job. Wouldn't worry about it at all.
7 Feb 2018 at 23:12 #11 opethdisciple opethdisciple Soldato Joined 18 May 2010 Posts 23,548 Location London nslookup
8 Feb 2018 at 07:23 #12 Steveocee Steveocee Soldato Joined 5 Nov 2011 Posts 5,578 Location Derbyshire Adblocker? Could even be worth spinning up a pihole DNS to run locally, *should* purge the stuff you don’t want before it even downloads it.
Adblocker? Could even be worth spinning up a pihole DNS to run locally, *should* purge the stuff you don’t want before it even downloads it.