Welcome to Laser Pointer Forums - discuss green laser pointers, blue laser pointers, and all types of lasers

LPF Donation via Stripe | LPF Donation - Other Methods

Links below open in new window

ArcticMyst Security by Avery

URGENT: Tracking IMG in posts!

Joined
May 14, 2013
Messages
3,438
Points
0
A few days ago I noticed that someone discovered that new member "darlene" was placing a hidden image in every post: http://rockbullet.tk/90/o.png/

It is a common practice to place a hidden image in email to track who opens the email and how many times they open it. Someone is doing this on LPF and could be creating a database of those who visit LPF.

Today I noticed some posts from new member "Leenon", they have the hidden image http://rockbullet.tk/94/o.png

Clearly these two are the same person. We should watch for new members that post short useless posts that sound like they were posted by a bot and check them for a hidden image.

I tried to track down who this person is but can't. There are both free and paid .TK domain names, this is a free one and the .TK registry protects the identity of those who register .TK domains. A Whois search only reveals the dot TK organization, except for one thing:



Domain name:
ROCKBULLET.TK

Organisation:
BV Dot TK
Dot TK administrator
P.O. Box 11774
1001 GT Amsterdam
Netherlands
Phone: +31 20 5315725
Fax: +31 20 5315721
E-mail: abuse: abuse@freenom.com, copyright infringement: copyright@freenom.com

Domain Nameservers:
NS1.HAWKHOST.COM
NS2.HAWKHOST.COM


Your selected domain name is a Free Domain. That means that,
according to the terms and conditions of Free Domain domain names
the registrant is BV Dot TK.

Due to restrictions in Dot TK 's Privacy Statement personal information
about the user of the domain name cannot be released.

ABUSE OF A DOMAIN NAME
If you want to report abuse of this domain name, please send a
detailed email with your complaint to abuse@freenom.com.
In most cases Dot TK responds to abuse complaints within one business day.

COPYRIGHT INFRINGEMENT
If you want to report a case of copyright infringement, please send
an email to copyright@freenom.com, and include the full name and address of
your organization. Within 5 business days copyright infringement notices
will be investigated.

Record maintained by: Dot TK Domain Registry



From the name servers that point to the domain we can tell who is hosting that domain/site:


[Nameserver 0 IP: 174.36.198.73
Target : ns1.hawkhost.com
City : Washington
Region : DC
Country: United States

Nameserver 1 IP: 74.86.9.53
Target : ns2.hawkhost.com
City : Dallas
Region : TX
Country: United States



They belong to a host caled Hawk Host Inc. https://www.hawkhost.com

This only means that whoever this is rents hosting or a server from https://www.hawkhost.com

It is hosted on a server in Dallas Texas belonging to Hawk Host, it is probably just a shared hosting account because there are 150 other sites on the same server:


IP Address: 198.252.98.30 United States
Hosting Service: "Hawk Host"
Hosting City: Dallas
Hosting Region: TX
Hosting Postal: 75247
Domain Created:
Domain Expires:
Domain Life: 0
Est Value: $112.26
Speed: Average (1349ms)

150 Other WebSites On This Server



That's all I could find out.

Alan
 





Trevor

0
Joined
Jul 17, 2009
Messages
4,386
Points
113
While I agree with you that this is definitely a flagrant version of tracking views (by using a hidden image), this kind of tracking can also be done by placing an image from a remote server in your signature.

This user should certainly be shown the door, but when you're on the internet you're unfortunately always open to this kind of thing.

Trevor
 
Last edited:
Joined
Sep 12, 2007
Messages
9,399
Points
113
The image from rockbullet.tk is all over the web though, not just LPF. Can a hosting site even see which site the link was followed from? I don't see how a seemingly random selection of web users' IPs would be useful.
 
Joined
May 14, 2013
Messages
3,438
Points
0
The image from rockbullet.tk is all over the web though, not just LPF. Can a hosting site even see which site the link was followed from? I don't see how a seemingly random selection of web users' IPs would be useful.

It's not one image, the images are in different numbered subdirectories of rockbullet.tk.

Yes it can, you can even create a MySQL database and with some PHP code automatically record IP addresses of everyone who views the image.

It's not a random selection of users IP addresses, it's specific to each image.

Alan
 
Joined
Jan 29, 2014
Messages
12,031
Points
113
I did that same thing about 20 years ago on another forum to discover sock puppets, effective, they never noticed...
 
Joined
Jul 4, 2012
Messages
2,834
Points
63
Yea they have been everywhere here for a while now. Report it and move on. Like Trevor said, we are on the internet; anything that we want hidden it already out there.
 

SteveT

0
Joined
Jan 20, 2015
Messages
252
Points
18
Discover sock puppets? Is that code for something?
A sock puppet is an account set up by an existing forum user that typically supports their main account. So for example I could set up a second account called JackD or JimB and enter into conversation with SteveT; I could rep him and agree with all he says; alternatively I may choose to argue with myself all day lol! If I were to get banned I could circumvent that ban by using one of my sock puppets until I was sprung. I am pretty sure there are a few active puppets on here now trying to recover from negative rep etc.
 
Last edited:
Joined
May 14, 2013
Messages
3,438
Points
0

That's what I was wondering, NSA/CIA/FBI, or maybe some foreign intelligence agency, Interpol, SIS(MI6), Mossad, this is a very international forum. I wish I had the IPs of these two members, I would trace them, if they aren't surfing anonymously I wouldn't be surprised if they were in someplace like Langley VA or Quantico VA or D.C. Go ahead and say I am a paranoid conspiracy theorist, but why would any individual want to know who is visiting LPF or any of the other 100 or so sites that site is doing this on? No one gathers info for no reason. They can tell what IP your coming from, what country your in, what OS and what browser your using, they can then trace your IP and tell what city your in and what Internet service provider your using and sometimes more. Maybe part of what they're looking for is who owns lasers and or guns, but then again it's possible there is some legitimate reason, if it's intelligence/federal law enforcement, they could just be looking for terrorist chatter and hoping to track them, or it could just be a business gathering data for marketing purposes, I can only guess.

Alan
 

Jstr

0
Joined
Feb 10, 2014
Messages
347
Points
0
That two computer-generated sounding names registered and posted these within a few days makes me agree with you. There's clear motivation for an agency to do it. Would it be enough simply to not click on these?
 
Joined
May 14, 2013
Messages
3,438
Points
0
That two computer-generated sounding names registered and posted these within a few days makes me agree with you. There's clear motivation for an agency to do it. Would it be enough simply to not click on these?

No they are embedded in the posts and loaded by your browser everytime you view it, they are invisible so that you don't know it's there.

Alan
 
Joined
Jan 18, 2009
Messages
1,443
Points
83
Is there a pattern to the threads they post in? Or are they just picking random active threads? Do the numbers correlate to anything?

lucillemay's numbers are all different: 98,96,99


Today, 05:04 PM
Gun Discussion
Posted By lucillemay
Re: Gun Discussion
While I'm not a fan of mentally unstable people getting guns
http://rockbullet.tk/98/o.png


Today, 05:03 PM
the lowest power laser can kill the Mosquito
Posted By lucillemay
Re: the lowest power laser can kill the Mosquito
he 200mW red from DX should take care of mosquitos
http://rockbullet.tk/96/o.png


Today, 05:02 PM
Sticky: FAIL THREAD!!!!
Posted By lucillemay
Re: Fail thread!!!!
i got pure confused at the sound for the first one
http://rockbullet.tk/99/o.png
 
Last edited:
Joined
May 14, 2013
Messages
3,438
Points
0
Is there a pattern to the threads they post in? Or are they just picking random active threads? Do the numbers correlate to anything?

lucillemay's numbers are all different: 98,96,99

This is very interesting. Yes the different numbers mean they are using a different .png file in each thread so they can track activity in each thread separately. I do not see a pattern to the choice of threads.

Alan
 




Top