Tracing IP addresses...

Jun 05, 2003 19:28

Inspired by this statement by msscribe, this is a response of sorts to this posting on gryffindortower which is claiming proof that two individuals are the same based on lists of IP addresses. I’ve looked up all the addresses mentioned using DNS (matching forward and reverse) and WHOIS (using whois.arin.net initially and rwhois.verio.net for more specific information on Verio addresses).
68.82.0.0-68.82.255.255 = Comcast Cable Communications, Inc. 68.82.67.208 = pcp01484347pcs.frncht01.de.comcast.net 130.94.107.128-130.94.107.255 = Anonymizer 130.94.107.137 = (No reverse DNS) 130.94.123.160-130.94.123.191 = Anonymizer 130.94.123.171 = (No reverse DNS) 167.21.0.0-167.21.255.255 = STATE OF DELAWARE 167.21.1.228 = eduproxy2.k12.de.us. 167.21.1.230 = eduproxy3.k12.de.us. 168.143.113.0-168.143.113.255 = Anonymizer 168.143.113.142 = (No reverse DNS) 168.143.123.64-168.143.123.127 = Anonymizer 168.143.123.83 = (No reverse DNS) 168.143.123.88 = (No reverse DNS) 209.234.128.0-209.234.223.255 = GST Telecom / Time Warner Telecom 209.234.157.44 = 209-234-157-44.gen.twtelecom.net 209.234.157.68 = 209-234-157-68.gen.twtelecom.net 209.234.157.104 = 209-234-157-104.gen.twtelecom.net 209.234.157.106 = 209-234-157-106.gen.twtelecom.net 209.234.157.228 = 209-234-157-228.gen.twtelecom.net 209.234.160.75 = 209-234-160-75.gen.twtelecom.net OK, so we have a whole bunch of addresses mapping to Anonymizer - clearly traffic coming from these addresses could be anyone. The various similar GST Telecom addresses (usually multiple for one person) are highly suggestive of dialup - in which case you could justify pointing fingers if two identities were seen on that address at virtually identical times - but equally they could be some form of proxy or cache servers. The "State of Delaware" addresses map to "eduproxy..." which it seems clear to me are proxy servers, most likely for (some of) the state's schools - again, any number of people could be behind those proxies.
The only address which may well map to a single location if the Comcast one (but that is merely speculation). This is apparently the address that was used by fermatojam to sign up at Gryffindor Tower - but wasn't Fermatojam originally a real Stalker whose accounts were only later misused by others (as described in this post on the GT LJ, which would surely mean that that address is associated with the *real* Fermatojam - and this address is only seen on one other person in that list, pottersginny.
    To summarise:
  • PottersGinny and msscribe have both used Anonymizer
  • PottersGinny, msscribe, clarabella21, sarahkjames and melodyannsings have all used (most likely) dialup connections through GST Telecom.
  • Fermatojam (unknown whether real or impersonated), MelodyAnnSings and "Kellie" have all used (most likely) an educational establishment in Delaware
  • Fermatojam (presumably real) and PottersGinny have both used the same Comcast IP address (possibly a cable modem)
The only remotely convincing connection I can draw from this evidence alone is between the real Fermatojam and PottersGinny - and even that relies on a couple of assumptions. The claim that "all these posts were made from msscribe's computer" seems ludicrous.
Previous post Next post
Up