November 27th, 2002, 10:02 AM
Tracing Trace Route
I was wondering if there was anyway to trace if your being trace routed. The only way i could think of is if you had some control over the way that you went to the host, and recorded all the ICMP packets that can your way......
other than that i dunno
November 27th, 2002, 10:10 AM
ummm, maybe its just because im tired, but you wanna know if you can trace someone who is trace routing you? if so im pretty sure you could, a port blocker or firewall would show them trying to trace you and you could trace the IP and tell there ISP, but if thats not what you mean could you maybe edit your post so its a lil more clear? iv always been against people saying "i wanna do stuff with this thingy how do i do it?" hehe
November 27th, 2002, 10:11 AM
There are programs like fakeroute that can change the traceroute people do on you..
other then that I dunno..
ASCII stupid question, get a stupid ANSI.
When in Russia, pet a PETSCII.
Get your ass over to SLAYRadio
the best station for C64 Remixes !
November 27th, 2002, 10:24 AM
Where this came up was that me and a friend was talking about finding out if you were being trace routed, and then change the route or break it some how. We thought you would have to comprimise some sytems and break the route.......but were not really into that kinda thing so i was wondering if there were other ways to do it.
November 27th, 2002, 10:35 AM
id reccommend a firewall or port blocker or both to you, some walls will actually tell you who and what is trying to trace you and block it. http://www.downloads.com is a good place to look at firewalls, not only can you download them you can read reviews.
November 27th, 2002, 11:20 AM
Or you could just use an anonymous proxy . Then the furthest they could trace you is to the proxy ip. If you use windows have a look at http://www.multiproxy.org/. They have a free program which will enable you to use anonymous proxies while browsing. Obviously this wont work on irc but hey its free
November 27th, 2002, 11:32 AM
K thnx for the posts ppl.
Yeah was thinking about the proxy issue. You can use proxies while browsing by going into internet options and lan settings then proxy. And the same with IRC. Also a number of programs has forwarding with proxies.
Im sure there are hundreads of proxy tut's out there, so i wont say much.
But thnx again for the info, and ill try that fake route and report how it goes
November 27th, 2002, 04:00 PM
A Trace route is just a modified ping packet (ICMP ECHO_REQUEST). The trace route program sends a ping to your address with TTL (Time To Live) set to one. The device on the first hop receives the packet with the TTL of one, decrements it to zero and replies back to the sender with a "time exceeded". The Trace route program then examines the return packet to see what device is one hope away. A new ping packet is then generated with a TTL of 2 and sent on it's way to find the next hop.
Monitor your ICMP traffic as you suggested and watch for ICMP ECHO_REQUEST's with a TTL of one. The default starting TTL on an ICMP packet is 255 so chances are anything with a TTL of one is probably a trace route.
was wondering if there was anyway to trace if your being trace routed
If you simply want to make sure that you can not be trace routed block all ICMP or ICMP ECHO_REQUEST traffic at your firewall and the "time exceeded" packet will not be returned.
Now that you know what you are looking for you can send back modified "time exceeded" message with spoofed information about your location to the requester, but you can't change the rest of the route since it was reported back to the sender before the last packet got to your location.
me and a friend was talking about finding out if you were being trace routed, and then change the route or break it some how.
If you receive something that says \'Send this to everyone you know,\' pretend you don\'t know me.
November 28th, 2002, 02:33 AM
You would not only have to drop incoming ICMP packets, but also UDP packets if the trace route is being performed by a *nix machine.
[glowpurple]There were so many fewer questions when the stars where still just the holes to heaven - JJ[/glowpurple] [gloworange]I sure could use a vacation from this bull$hit, three ringed circus side show of freaks. - Tool. [/gloworange]
November 28th, 2002, 04:44 AM
your absolutly right SoggyBottom thats why devices like fakeroute (which take advantage of the unix udp packet) only work if the tracert comes from a *nix machine and are absolutly useless against a windows box.
Bukhari:V3B48N826 “The Prophet said, ‘Isn’t the witness of a woman equal to half of that of a man?’ The women said, ‘Yes.’ He said, ‘This is because of the deficiency of a woman’s mind.’”