{"id":44203,"date":"2015-04-20T07:00:00","date_gmt":"2015-04-20T21:00:00","guid":{"rendered":"https:\/\/blogs.msdn.microsoft.com\/oldnewthing\/2015\/04\/20\/how-to-find-the-ip-address-of-a-hacker-according-to-csi-cyber\/"},"modified":"2021-07-20T14:11:01","modified_gmt":"2021-07-20T21:11:01","slug":"20150420-00","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/oldnewthing\/20150420-00\/?p=44203","title":{"rendered":"How to find the IP address of a hacker, according to CSI: Cyber"},"content":{"rendered":"<p>The episode of the television documentary <a href=\"http:\/\/www.cbs.com\/shows\/csi-cyber\/\"> <i>CSI: Cyber<\/i><\/a> which aired <a href=\"http:\/\/www.cbs.com\/shows\/csi-cyber\/video\/7FD54750-B536-C22B-3A14-B60512718034\/csi-cyber-the-evil-twin\/\"> on CBS last Wednesday<\/a> demonstrated an elite trick to obtaining a hacker&#8217;s IP address: Extract it from the email header.<\/p>\n<p>Here&#8217;s a screen shot from time code 14:35 that demonstrates the technique.<\/p>\n<pre style=\"font-family: monospace; color: #e08080; overflow: auto; white-space: pre; line-height: normal;\">\r\n<span style=\"background-color: black;\">&lt;meta id<span style=\"color: white;\">=\"<\/span><span style=\"color: #84acc4;\">viewport<\/span><span style=\"color: white;\">\"<\/span> content<span style=\"color: white;\">=\"\"<\/span> name<span style=\"color: white;\">=\"<\/span><span style=\"color: #84acc4;\">viewport<\/span><span style=\"color: white;\">\"<\/span>&gt;&lt;\/m<\/span>\r\n<span style=\"background-color: black;\">&lt;link href<span style=\"color: white;\">=\"<\/span><span style=\"color: #84acc4;\">y\/images\/favicon.ico<\/span><span style=\"color: white;\">\"<\/span> rel<span style=\"color: white;\">=\"<\/span><span style=\"color: #84acc4;\">shortcut ic<\/span><\/span>\r\n<span style=\"background-color: black;\">&lt;link href<span style=\"color: white;\">=\"<\/span><span style=\"color: #84acc4;\">y\/styles.css?s=1382384360<\/span><span style=\"color: white;\">\"<\/span> type<span style=\"color: white;\">=\"<\/span><span style=\"color: #84acc4;\">text\/<\/span><\/span>\r\n<span style=\"background-color: black;\">&lt;link href<span style=\"color: white;\">=\"<\/span><span style=\"color: #84acc4;\">y\/mail.css?s=1382384360<\/span><span style=\"color: white;\">\"<\/span> type<span style=\"color: white;\">=\"<\/span><span style=\"color: #84acc4;\">text\/cs<\/span><\/span>\r\n<span style=\"background-color: red; color: white;\">&lt;hidden: ip: 951.27.9.840 &gt; &lt; echo;off;&gt;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span>\r\n<span style=\"background-color: black; color: #808080;\">&lt;!--if lte IE 8&gt;&lt;link rel=\"stylesheet\" type=\"text\/<\/span>\r\n<span style=\"background-color: black; color: #808080;\">&lt;!--if lte IE 7&gt;&lt;link rel=\"stylesheet\" type=\"text\/<\/span>\r\n<span style=\"background-color: black;\">&lt;link href<span style=\"color: white;\">=\"<\/span><span style=\"color: #84acc4;\">plugins\/jqueryui\/themes\/larry\/jquery-u<\/span><\/span>\r\n<span style=\"background-color: black;\">&lt;link href<span style=\"color: white;\">=\"<\/span><span style=\"color: #84acc4;\">plugins\/jqueryui\/themes\/larry\/ui.js?s=<\/span><\/span>\r\n<\/pre>\n<p>This technique is so awesome I had to share it.<\/p>\n<p><!--\n\n\n\n\n<P>\nI think the it would have been better if the bad guy's\nIP address were 127.x.x.x or (less obviously)\n192.168.x.x or (even less obviously) 203.0.113.x.\nThen the script kiddies watching the show would go nuts trying to DoS that guy. \n<\/P>\n\n\n\n\n--><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>According to television.<\/p>\n","protected":false},"author":1069,"featured_media":111744,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[103],"class_list":["post-44203","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-oldnewthing","tag-non-computer"],"acf":[],"blog_post_summary":"<p>According to television.<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts\/44203","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/users\/1069"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/comments?post=44203"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts\/44203\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/media\/111744"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/media?parent=44203"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/categories?post=44203"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/tags?post=44203"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}