Help Tracing IP: Uncle needs help

StarsFan4Life

Golden Member
May 28, 2008
1,199
0
0
Everyone,

My uncle and I are in need of some expert help. My uncle is living and working in Iraq and just went through a nasty divorce. The ex-wife is just nuts...plain and simple. I used to like her until I found some things out.

Anyways, I got a call from him a few weeks ago asking if there was a way to trace where an email was sent from. He thinks it was his ex-wife, but we are not sure. Someone logged into his Yahoo! email account and sent everyone in his address list porno - just so happens the email "went" to his ex-wife and one of his daughters. Now the ex-wife has the judge basically saying that if it was him, he won't be allowed to see his children (when he returns from Iraq). He DID not send the email and so far all have pointed to her sending them from his email address (she knew his login information to Yahoo!).

Here are the email headers I was able to get from one of my cousins who actually received the email:

X-Message-Delivery: Vj0zLjQuMDt1cz0wO2k9MDtsPTA7YT0x
X-Message-Status: n:0
X-SID-PRA: John Doe<XXXXX@YAHOO.COM>
X-Message-Info: R00BdL5giqp+ASWiiiiklSMzMa10fZupk3Fb9NiVmI5r4Po5armbqOI798wD/QZo6pVfBnc4AQL5Z7LdCPyN6042pfH/olZJ
Received: from web54504.mail.re2.yahoo.com ([206.190.49.154]) by bay0-mc3-f22.bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.2668);
Thu, 3 Apr 2008 19:58:36 -0700
Received: (qmail 17316 invoked by uid 60001); 4 Apr 2008 02:58:36 -0000
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws;
s=s1024; d=yahoo.com;
h=X-YMail-OSG:Received:Date:From:Subject:To:MIME-Version:Content-Type:Content-Transfer-Encoding:Message-ID;
b=xnbKrZW8NRUf/6Mw+3/xueNpUW+WL+v3lCOw3xUA1F8OUctGCZdS/hXW2yEFTdFA4142A6iH8hwLls7IHDc6bSLs7NzbUwMCaN2cfZK9hc9A4FhWGw8m+QwdmFZF2PtChdSSkh60LYUxWUVsmGKLGlZR/zjoD5MBKReP997VDUg=;
X-YMail-OSG: GvyQS0YVM1k4lyNRxYtvqLfVTUM1tSQtMVzMfHFdMEE.Xr8bCJREyk7o0aLsmk6wL4TT_XMDvkdGOBen_MH81xU5vsUi4EYdG2DcdxnO5Q--
Received: from [24.153.180.26] by web54504.mail.re2.yahoo.com via HTTP; Thu, 03 Apr 2008 19:58:35 PDT
Date: Thu, 3 Apr 2008 19:58:35 -0700 (PDT)
From: John Doe<XXXXX@YAHOO.COM>
Subject: Fwd: Guess what today is ??
To: ALL EMAIL ADDRESSES, BUT I HAVE REMOVED THEM AS I DON'T WANT THEM GETTING INTO THE WRONG HANDS
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="0-421383848-1207277915=:16735"
Content-Transfer-Encoding: 8bit
Message-ID: <44922.16735.qm@web54504.mail.re2.yahoo.com>
Return-Path: XXXXX@yahoo.com
X-OriginalArrivalTime: 04 Apr 2008 02:58:36.0601 (UTC) FILETIME=[C6E2CA90:01C895FF]

--0-421383848-1207277915=:16735
Content-Type: multipart/alternative; boundary="0-712704726-1207277915=:16735"

--0-712704726-1207277915=:16735
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: 8bit



Now, if I am not mistaken, yahoo.com received the actual email from 24.153.180.26, correct? If so, a tracert shows the following information from my IP:


Tracing route to rrcs-24-153-180-26.sw.biz.rr.com [24.153.180.26]
over a maximum of 30 hops:

1 <1 ms <1 ms <1 ms 192.168.0.1
2 12 ms 12 ms 11 ms cpe-XXX.XXX.XXX.XXX.tx.res.rr.com [XXX.XXX.XXX.XXX]
3 10 ms 11 ms 12 ms gig1-2.dllatxcrl-rtr2.tx.rr.com [XXX.XXX.XXX.XXX]
4 8 ms 8 ms 11 ms gig4-0-0.dllatxchn-rtr6.tx.rr.com [70.125.217.101]
5 18 ms 18 ms 19 ms gig0-1-0.hstntxl3-rtr1.texas.rr.com [72.179.205.74]
6 25 ms 24 ms 22 ms gig3-0-0.austtxrdcsc-rtr1.austin.rr.com [72.179.205.79]
7 21 ms 21 ms 23 ms gig1-0-0.austtxa-10k1.austin.rr.com [24.27.13.117]
8 30 ms 32 ms 35 ms rrcs-24-153-180-26.sw.biz.rr.com [24.153.180.26]

I also did a lookup of the address on a few sites, but they were pretty inconsistent. Can anyone help me PINPOINT where this came from or a remote location of where it came from? As you can tell, he obviously didn't send the email since he is in IRAQ! Your help is greatly appreciated!
 

Aimster

Lifer
Jan 5, 2003
16,129
2
0
People who go to Iraq are highly respected.

I doubt the judge will believe this woman unless she too has been to Iraq
 

StarsFan4Life

Golden Member
May 28, 2008
1,199
0
0
Regardless, he is trying to fight to clear his name and possibly take legal action against her. Your help is greatly appreciated!
 

Kirby64

Golden Member
Apr 24, 2006
1,485
0
76
Thing is, it's roadrunner IP. They use dynamic IPs, so unless roadrunner kept a record of it, there's no way to accurately prove who sent it. They might keep logs so if u match the time it was sent to the IPs assigned at that time you could get somewhere... but all of this is going to likely need a court order to even start looking into getting these records.

One thing you can accurately say is that your Uncle DIDN'T send the email. Roadrunner isn't in Iraq :p

It's going to be hard to prove it's the ex-wife, so I'd just say you need to focus on proving your Uncle is innocent.
 

QED

Diamond Member
Dec 16, 2005
3,428
3
0
Without even geolocating the IP address, the tracert indicates this came from a RoadRunner Business-class cable internet subscriber near Austin, Texas.

These IPs are typically NOT dynamically assigned, at least not by TWC. It could be a normal business... it could be a Starbucks or a hotel which offers Internet access to its customers.

I'm currently running nmap on that subnet to see what services I can find running that might divulge a bit more information...
 

wetcat007

Diamond Member
Nov 5, 2002
3,502
0
0
I had no clue yahoo included your IP address in the message header, that's good to know I guess lol.
 

StarsFan4Life

Golden Member
May 28, 2008
1,199
0
0
So is there any laws against logging into another person's email account and sending pornographic pictures to everyone in their contact list?
 

StarsFan4Life

Golden Member
May 28, 2008
1,199
0
0
Originally posted by: QED
Without even geolocating the IP address, the tracert indicates this came from a RoadRunner Business-class cable internet subscriber near Austin, Texas.

These IPs are typically NOT dynamically assigned, at least not by TWC. It could be a normal business... it could be a Starbucks or a hotel which offers Internet access to its customers.

I'm currently running nmap on that subnet to see what services I can find running that might divulge a bit more information...

Is there a way I can see who might have been logged into their laptop (I assume) and sent the email?
 

arkcom

Golden Member
Mar 25, 2003
1,816
0
76
Originally posted by: StarsFan4Life
Originally posted by: Rubycon
Sent from a Holiday Inn express in Austin, Texas?

Can you explain how you figured this out? I would like to know how I can do this myself.

She doesn't know, she just stayed at a Holiday Inn Express last night. :laugh:
 

StarsFan4Life

Golden Member
May 28, 2008
1,199
0
0
Originally posted by: arkcom
Originally posted by: StarsFan4Life
Originally posted by: Rubycon
Sent from a Holiday Inn express in Austin, Texas?

Can you explain how you figured this out? I would like to know how I can do this myself.

She doesn't know, she just stayed at a Holiday Inn Express last night. :laugh:

Lol....nice.

Seriously though.
 

FDF12389

Diamond Member
Sep 8, 2005
5,234
7
76
Your past the important part, proving it wasnt him. Its going to be really hard to prove it was her.
 

tranceport

Diamond Member
Aug 8, 2000
4,168
1
81
www.thesystemsengineer.com
Originally posted by: StarsFan4Life
So is there any laws against logging into another person's email account and sending pornographic pictures to everyone in their contact list?

There are probably some generic "unauthorized access" laws that may come into effect.

I agree that the ip address 24.153.180.26 is in Austin Texas. Use the website posted above.. http://www.geobytes.com/IpLocator.htm?GetLocation and in the "Ip Address to locate" field enter the ip address and click submit.

You will see on the right that at 98% certainty this system believes the ip address is in Austin TX.

You're best bet is to use the information to prove your uncle did not send the email.


If you are still wanting to prove/find out if the ex wife did in fact do it.. You will likely need some subpoenas to TWC in order to find out who had the ip address on this date unless it is a static then they will just confirm who has owned the ip and for how long. Then you can go to this person/business and subpoena them for information as to who accessed the website. This may be a dead end unless they have a record of web traffic requests. TWC will be able to point you to their customer who has the ip address though.
 

bamacre

Lifer
Jul 1, 2004
21,029
2
61
Originally posted by: tranceport
Originally posted by: StarsFan4Life
So is there any laws against logging into another person's email account and sending pornographic pictures to everyone in their contact list?

There are probably some generic "unauthorized access" laws that may come into effect.

I agree that the ip address 24.153.180.26 is in Austin Texas. Use the website posted above.. http://www.geobytes.com/IpLocator.htm?GetLocation and in the "Ip Address to locate" field enter the ip address and click submit.

You will see on the right that at 98% certainty this system believes the ip address is in Austin TX.

You're best bet is to use the information to prove your uncle did not send the email.


If you are still wanting to prove/find out if the ex wife did in fact do it.. You will likely need some subpoenas to TWC in order to find out who had the ip address on this date unless it is a static then they will just confirm who has owned the ip and for how long. Then you can go to this person/business and subpoena them for information as to who accessed the website. This may be a dead end unless they have a record of web traffic requests. TWC will be able to point you to their customer who has the ip address though.

That site says my IP is in Shreveport, LA. 90% Certainty.

They are certainly wrong. :D

And I have a static IP.
 

erub

Diamond Member
Jun 21, 2000
5,481
0
0
It also has me 88% certain as being in Little Rock, Arkansas..a good 323 miles away and a stateline away :p
 

Auggie

Golden Member
Jul 18, 2003
1,379
0
0
Damn, what a conniving bitch. Much respect to your Uncle. Hope things work out well for him.