Finding the real id of someone who posted something.

Discussion in 'Computer Support' started by Jim Tiberio, Apr 23, 2004.

  1. Jim Tiberio

    Jim Tiberio Guest

    I saw a post show on a newsgroup I frequent along with about
    ten other newsgroups. The problem with this one was that it showed up as
    being posted by myself. Is there anyway to find out who posted it?
    Jim Tiberio, Apr 23, 2004
  2. Jim Tiberio

    Unk Guest

    View the headers. It will give SOME information about the poster.

    For example, YOUR headers have:
    Message-ID: <c6a08h$9rirk$>
    NNTP-Posting-Host: (
    X-Trace: 1082688593 10341236 I ([162059])
    X-Newsreader: Microsoft Outlook Express 6.00.2800.1158
    X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165

    A lookup gets:
    ISP/Who = Optimum Online
    TARGET: (
    IP Location: United States - Connecticut - Stratford - Optimum Online
    (cablevision Systems)

    Not enough to come visit you....
    Unk, Apr 23, 2004
  3. Jim Tiberio

    Jim Tiberio Guest

    Thanks, I have no idea how you gleaned that info but what does this tell

    From: Jim Tiberio <>
    Message-ID: <>
    Subject: March your way into the weekend!
    Date: Thu, 22 Apr 2004 22:45:00 GMT
    Approved: Jim Tiberio <>
    Organization: Nader for President 2004 - P.O. Box 18002, Washington, DC
    20036 - (202) 265-4000
    Reply-To: Jim Tiberio <>
    X-Newsreader: Microsoft Outlook Express 5.00.0810.800
    X-Original-Trace: 5430878035 05868 (22 Apr 2004 22:45:00 GMT)
    Followup-To: Poster
    Lines: 80
    X-Trace: 1082675810 16964
    Jim Tiberio, Apr 23, 2004
  4. Jim Tiberio

    Unk Guest

    ISP/Who = Optus Internet
    City = Burwood East
    State = Victoria
    Country = Australia (au)

    Unk, Apr 23, 2004
  5. Jim Tiberio

    Boomer Guest

    Go to and do a 'whois' search for

    Here's more info
    Boomer, Apr 23, 2004
  6. The chances of running down this person are virtually nonexistent. The buzz
    in the spam-fighting groups is that this is the work of Hipcrime, a
    well-known and notorious cracker group(?). The posts are all done through
    computers whose owners, through either sloppiness or lack of knowledge,
    have left them open as relay points ("open proxies" in techspeak). The
    originating computers are all hijacked Windows boxes whose owners, again,
    are unaware their machines are being used for nefarious activities. ALL of
    the "From" addresses are forgeries. This spam forgery is so widespread and
    obvious that an ISP that tried to cut you off for spreading it should be
    sued for terminal stupidity; I wouldn't worry about your ISP giving you
    flak over this.
    Gary G. Taylor, Apr 23, 2004
  7. Jim Tiberio

    trout Guest

    Jim Tiberio wrote:
    As mentioned; the line to look at is the "NNTP-Posting-Host:". You can go to any number of sites to do a Whois lookup
    when you have that number. I usually use
    Impersonation can be a problem in Usenet; there's not all that much
    you can do about it. If however, that is *your valid address* that was
    used; it makes it a case of forgery, rather than impersonation. This
    would likely be enough to terminate that person's account.
    Again, that address is .
    trout, Apr 23, 2004
  8. Jim Tiberio

    John Guest

    Unfortunately (and unrelated to this particular problem)
    stupidity does not seem to be terminal.
    John, Apr 26, 2004
  9. Jim Tiberio

    Guest Guest

    You haven't heard of the Darwin Award? Try
    Guest, Apr 26, 2004
  10. Jim Tiberio

    Demolitio Guest

    the last person who explained to me that people occassionally do stupid
    things...... walked into a stop sign while saying it.
    Demolitio, Apr 26, 2004
