GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Help.. Where is this ip from? 209.151.166.20 (https://gfy.com/showthread.php?t=1156416)

xxweekxx 12-08-2014 08:39 PM

Help.. Where is this ip from? 209.151.166.20
 
Someone with that IP 209.151.166.20 apparently used my correct gmail password to try to login to my gmail..

Gmail blocked it and sent me emails/text saying someone tried to login from unknown location..

Question is, who has that IP? and what do I do..

Nobody in the world knows my email password and it's very very complicated...

Jel 12-08-2014 08:45 PM

209.151.166.20 is a United States IP Address. See more about 209.151.166.20 now.

ExtremeBank_Adam 12-08-2014 08:46 PM

Locate IP Address Lookup Show on Map City of the IP 209.151.166.20

mineistaken 12-08-2014 08:48 PM

So if you would try to log in from vacation spot you would get your account locked? Some advanced feature? Just curious because I have been logging into mine from many different IPs.

TeenCat 12-08-2014 08:49 PM

whois says its in usa, some provider, there are contacts, abuse and so, tell them someone used their service to hack your email, maybe they can help you track him down or i dont think you have much more chances :) btw, wasnt it you, loging from mobile phone? :) have luck :)

xxweekxx 12-08-2014 08:51 PM

No it wasnt me.. Im not even in the united States, plus I was sleeping when this happened..

Whats freaking me out is they typed in the CORRECT password..

I dont know how to solve the problem.. Even if i change my password, someone still has my gmail password..

Horatio Caine 12-08-2014 08:52 PM

Looks like Juicy D Links is looking into hooking up with male contacts in your list.

TeenCat 12-08-2014 08:54 PM

man, how you know they have been in? and they cannot be in, when the access is blocked! and you have the pass only at gmail, unique? if yes, then it must be santa looking for gifts inspiration ... :2 cents:

xxweekxx 12-08-2014 08:58 PM

Quote:

Originally Posted by TeenCat (Post 20316778)
man, how you know they have been in? and they cannot be in, when the access is blocked! and you have the pass only at gmail, unique? if yes, then it must be santa looking for gifts inspiration ... :2 cents:

I got the email below to my original gmail, recovery email, and a text by cell phone so its legit.. Also the email link leads directly to google help file on how to change your password... The email says they USED MY PASSWORD..


Someone recently used your password to try to sign in to your Google Account - [email protected].

We prevented the sign-in attempt in case this was a hijacker trying to access your account. Please review the details of the sign-in attempt:

Tuesday, December 9, 2014 1:05:07 AM UTC
IP Address: 209.151.166.20
Location: United States


If you do not recognize this sign-in attempt, someone else might be trying to access your account. You should sign in to your account and reset your password immediately.

mineistaken 12-08-2014 09:00 PM

Quote:

Originally Posted by xxweekxx (Post 20316772)
No it wasnt me.. Im not even in the united States, plus I was sleeping when this happened..

Whats freaking me out is they typed in the CORRECT password..

I dont know how to solve the problem.. Even if i change my password, someone still has my gmail password..

I know it was not you. My question was - what if it have been you logging in from another country, would you get locked out?

dicknipples 12-08-2014 09:02 PM

It was me.

glowlite 12-08-2014 09:04 PM

Hard to believe you don't know how to drill down on an IP.

xxweekxx 12-08-2014 09:05 PM

Quote:

Originally Posted by mineistaken (Post 20316784)
I know it was not you. My question was - what if it have been you logging in from another country, would you get locked out?

not if you are using the same ol computer/cookies..

if i try from another country using my same laptop it lets me in..

otherwise it will ask you for recover questions..

xXXtesy10 12-08-2014 09:07 PM

but you are the best :(

xxweekxx 12-08-2014 09:12 PM

Quote:

Originally Posted by glowlite (Post 20316788)
Hard to believe you don't know how to drill down on an IP.

All i know how to do is find the location/network which shows some ISP in NYC..

Is there any further information you can get for me?

xxweekxx 12-08-2014 09:15 PM

Quote:

Originally Posted by xXXtesy10 (Post 20316792)
but you are the best :(

usually :) not time time :helpme

SilentKnight 12-08-2014 09:22 PM

Check your systems to see if there's a keylogger malware anywhere.

beenthereb4 12-08-2014 09:24 PM

sounds like a real who dunnit

TeenCat 12-08-2014 09:44 PM

Quote:

Originally Posted by xxweekxx (Post 20316783)
I got the email below to my original gmail, recovery email, and a text by cell phone so its legit.. Also the email link leads directly to google help file on how to change your password... The email says they USED MY PASSWORD..


Someone recently used your password to try to sign in to your Google Account - [email protected].

We prevented the sign-in attempt in case this was a hijacker trying to access your account. Please review the details of the sign-in attempt:

Tuesday, December 9, 2014 1:05:07 AM UTC
IP Address: 209.151.166.20
Location: United States


If you do not recognize this sign-in attempt, someone else might be trying to access your account. You should sign in to your account and reset your password immediately.

hey man, i am sorry ...

"We prevented the sign-in attempt in case this was a hijacker trying to access your account." - Google Search

but looks like good for you :winkwink:

TeenCat 12-08-2014 09:46 PM

Gmail "suspicious sign-in prevented" message - is it legit? - Web Applications Stack Exchange

Quote:

I am the Gmail Community Manager, and I can confirm that we do send email notifications in certain cases such as described here.
:winkwink:

WDF 12-08-2014 10:52 PM

Where else did you use the password associated with the account?

Have you used this password for an external account associated with the email?

Do you have a password list on a server or your pc/mobile device?

Has your PC been compromised by something not picked up by your security software?

TeenCat 12-08-2014 10:58 PM

Quote:

Originally Posted by TeenCat (Post 20316824)

oh sorry, long night shift, so it means nothing, they are sending similar emails, i have read it wrong previously ... :Oh crap :2 cents:

DannyS 12-08-2014 11:14 PM

You've been hacked :)

CPA-Rush 12-08-2014 11:26 PM

maybe prank email ?

IP Address: 209.151.166.20

CPA-Rush 12-08-2014 11:34 PM

do u use vps ?
-sign out the other sessions
-change the alternative email and other info
-for extra level of safety/ security layer add your cellphone to recover the account if anything happened


make sure he is not in your account u can see who signed in. contact gmail cs

fuck him!

jimmycastor 12-09-2014 03:22 AM

you sure its not an email scam and that this email has been sent from a legit gmail (google) adress
, check the senders adress twice before you clickthu any link within an email that you receive


those exploiters are getting very creative lately

Emil 12-09-2014 03:44 AM

Quote:

Originally Posted by xxweekxx (Post 20316758)
Someone with that IP 209.151.166.20 apparently used my correct gmail password to try to login to my gmail..

Gmail blocked it and sent me emails/text saying someone tried to login from unknown location..

Question is, who has that IP? and what do I do..

Nobody in the world knows my email password and it's very very complicated...

Might just be a bot that found your email somehow and is trying to login with common passwords. The IP is probably a proxy.

iSpyCams 12-09-2014 06:00 AM

It's a corporate, static IP and usually when I see those related to a signup attempt it is a proxy server, and most likely fraud.

The owner of that IP address is "GalaxyVisions" in Brooklyn, a hosting company so most likely someone has a VPN set up on their server so they can hack and/or spam without revealing their real location.

Previously a domain called "dvdmagnet.com" was set up on that IP but changed in Sept 2013 when it appears the domain was parked. Maybe the previous owner of that domain still has control of the server, but who knows really. Possibly someone has a squid server running there to leverage the IP's for black hat stuff or potentially its just an exploit and the owner of the box has no idea his shit is being used to hack.

seeandsee 12-09-2014 07:53 AM

Use 2step verification, when you log from unsecure device, you get sms with pin code, confirm it and then you can get into gmail

candyflip 12-09-2014 08:20 AM

2 Step Verification ftw!

I use an app on my phone called Authy that updates my auth codes every few minutes and keeps them within easy reach.

XXXtrailers 12-09-2014 08:22 AM

change your pass

ruff 12-09-2014 08:28 AM

Quote:

Originally Posted by candyflip (Post 20317308)
2 Step Verification ftw!

I use an app on my phone called Authy that updates my auth codes every few minutes and keeps them within easy reach.

Everyone should be doing that. I use 2 factor authentication as well using Google Authenticator. I also have a VPN account. Can't be too careful these days.

Barry-xlovecam 12-09-2014 03:27 PM

barry@deathstar9:~$ dig 209.151.166.20

; <<>> DiG 9.9.5-3-Ubuntu <<>> 209.151.166.20
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 62123
;; flags: qr aa rd ra ad; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0

;; QUESTION SECTION:
;209.151.166.20. IN A

;; ANSWER SECTION:
209.151.166.20. 0 IN A 209.151.166.20

;; Query time: 1 msec
;; SERVER: 127.0.1.1#53(127.0.1.1)
;; WHEN: Tue Dec 09 17:24:05 EST 2014
;; MSG SIZE rcvd: 48

barry@deathstar9:~$ whois 209.151.166.20

#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#
# If you see inaccuracies in the results, please report at
# ARIN - American Registry for Internet Numbers
#


#
# The following results may also be obtained via:
# http://whois.arin.net/rest/nets;q=20...se&ext=netref2
#

NetRange: 209.151.160.0 - 209.151.175.255
CIDR: 209.151.160.0/20
NetName: GALAX-NETBLK-14
NetHandle: NET-209-151-160-0-1
Parent: NET209 (NET-209-0-0-0-0)
NetType: Direct Allocation
OriginAS: AS31797
Organization: Galaxyvisions Inc (GALAX-6)
RegDate: 2009-04-20
Updated: 2012-02-24
Ref: http://whois.arin.net/rest/net/NET-209-151-160-0-1

OrgName: Galaxyvisions Inc
OrgId: GALAX-6
Address: 882 3rd avenue 8th floor
City: Brooklyn
StateProv: NY
PostalCode: 11232
Country: US
RegDate: 2003-12-15
Updated: 2009-04-17
Ref: http://whois.arin.net/rest/org/GALAX-6

ReferralServer: rwhois://rwhois.galaxyvisions.com:4321

OrgTechHandle: GALAX1-ARIN
OrgTechName: Galaxyvisions NOC
OrgTechPhone: +1-201-227-2072
OrgTechEmail: [email protected]
OrgTechRef: http://whois.arin.net/rest/poc/GALAX1-ARIN

OrgAbuseHandle: GALAX2-ARIN
OrgAbuseName: Galaxyvisions Abuse
OrgAbusePhone: +1-201-227-2072
OrgAbuseEmail: [email protected]
OrgAbuseRef: http://whois.arin.net/rest/poc/GALAX2-ARIN

RAbuseHandle: GALAX2-ARIN
RAbuseName: Galaxyvisions Abuse
RAbusePhone: +1-201-227-2072
RAbuseEmail: [email protected]
RAbuseRef: http://whois.arin.net/rest/poc/GALAX2-ARIN

RTechHandle: GALAX1-ARIN
RTechName: Galaxyvisions NOC
RTechPhone: +1-201-227-2072
RTechEmail: [email protected]
RTechRef: http://whois.arin.net/rest/poc/GALAX1-ARIN


#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#
# If you see inaccuracies in the results, please report at
# ARIN - American Registry for Internet Numbers
#



Found a referral to rwhois.galaxyvisions.com:4321.

%rwhois V-1.5:003eff:00 rwhois.galaxyvisions.com (by Network Solutions, Inc. V-1.5.9.5)
network:Class-Name:network
network:ID:GALAX-NETBLK-4 209.151.160.0/20
network:Auth-Area:209.151.160.0/20
network:Network-Name:barry_kunst-209.151.166.16
network:IP-Network:209.151.166.16/28
network:IP-Network-Block:209.151.166.16-209.151.166.31
network:Organization;I:barry_kunst
network:Tech-Contact;I:[email protected]
network:Admin-Contact;I:[email protected]
network:Created:20141108
network:Updated:20141108
network:Updated-By:[email protected]

network:Class-Name:network
network:ID:GALAX-NETBLK-4.209.151.160.0/20
network:Auth-Area:209.151.160.0/20
network:Network-Name:GALAX-NETBLK-4
network:IP-Network:209.151.160.0/20
network:IP-Network-Block:209.151.160.0 - 209.104.175.255
network:Organization;I:Galaxyvisions Inc
network:Tech-Contact;I:GALAX1-ARIN
network:Admin-Contact;I:GALAX1-ARIN
network:Created:20090503
network:Updated:20090503
network:Updated-By:[email protected]

%ok
barry@deathstar9:~$


All times are GMT -7. The time now is 10:40 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc