nanog mailing list archives

Re: Tracing network procedure for stolen computers


From: Peter Dambier <peter () peter-dambier de>
Date: Mon, 12 Jun 2006 22:30:52 +0200


Colin Johnston wrote:
Hi folks,
Quick security tracing question, flame me if you think offnetwork topic.

Earlier this month my daughters Ibook was stolen, oh well that is life I
guess.
Anyway updated mail server software for full debug and IP log since noticed
that mail account was accessed yesterday.
I am now hoping it is access'd again, system was setup to pull each min so
when they(thugs) access internet again hopefully will honeytrap IP number.
What does one do next ? I guess inform police etc but would this be too slow
?? Do I contact ARIN/RIPE contacts direct ??

I know about software that should have been installed for tracing if stolen
but wondered about in the real network world how useful this was and if any
items recovered ??


Colin Johnston
Satsig sysadmin

Apple have their own good ideas.

Besides a VoIP phone software or something like no-ip.com is good to
permanently know what ip-address the toy has.

Knowing the ip you can traceroute to guess what continent, state, province
it is, via its final router. The police and the owner of the final router
should do the rest.

Bad idea :) have some child porn on the box and mail it to the police.
They will trace it very fast.

--
Peter and Karin Dambier
Cesidian Root - Radice Cesidiana
Graeffstrasse 14
D-64646 Heppenheim
+49(6252)671-788 (Telekom)
+49(179)108-3978 (O2 Genion)
+49(6252)750-308 (VoIP: sipgate.de)
mail: peter () peter-dambier de
mail: peter () echnaton serveftp com
http://iason.site.voila.fr/
https://sourceforge.net/projects/iason/


Current thread: