02.11.2014 Views

untangling_the_web

untangling_the_web

untangling_the_web

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

DID: 4046925<br />

UNCLA55IFIEDl1'F6R 6FFlel)!(L USE 6NL'f<br />

Of special note are <strong>the</strong> two IP addresses that appear in <strong>the</strong>se records as mail<br />

servers: 195.128.64.9 and 212.5.80.6. The first resolves to Macomnet in Moscow<br />

and <strong>the</strong> second to kaspersky.com, a domain name registered with Tucows.com.<br />

Sounds like it might be in <strong>the</strong> US.<br />

4. Where is kaspersky.com or 212.5.80.6 physically located?<br />

This is usually harder to determine because truly accurate geolocation tools are not<br />

available for free on <strong>the</strong> Internet. However, we can get some pretty good clues from<br />

<strong>the</strong> network analysis tool traceroute. Below is <strong>the</strong> traceroute to kaspersky.com using<br />

Domain Dossier. Notice in particular <strong>the</strong> last three hops before reaching 212.5.80.6:<br />

<strong>the</strong>y are Frankfurt, Germany (frankfurt1.de.alter.net), Moscow (msk.macomnet.net),<br />

and Macomnet's address 195.128.64.9 in Moscow. Traceroute shows <strong>the</strong> name of<br />

routers along <strong>the</strong> path <strong>the</strong> data is traveling, and <strong>the</strong>se routers frequently (but<br />

certainly not always) use airport codes (e.g. LON, ATL). Below, for example,<br />

dca4.alter.net is almost certainly in <strong>the</strong> Washington, DC, area. There is much more<br />

that can be learned from traceroutes, a topic covered in <strong>the</strong> next section.<br />

Tracercute<br />

Tracing route to st.kesperskv.eom [212.5.80.6]...<br />

hop rti rtt rtt 'ip,address fully qual,ified domainriame<br />

1 0 0 1 216.46.228.229 port-216-3073253-e5128 .devicss .dstarsturn.corn<br />

2 0 0 a 64,29,192,145 POft-64-1949841-2ztooresoect.devices .datarsturnmIT<br />

3 0 0 0 54.29.192.226 daa.g921.isob .datareturn.com<br />

4 0 0 0 168,215.241,133 hagg-Ol-aeO-1iJ01.dlfw rwtelscom.net<br />

5 o a 0 65.192.253,124 core-02-

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!