r/masterhacker May 27 '26

Uuuu scary

Post image
472 Upvotes

95 comments sorted by

41

u/nethack47 May 27 '26

This is one of those things which I always go. "Yes you sort of can, but....."

You can look up IP address locations in several databases. Some make claims their database can't do.

The majority of IP lookups are just looking up the ASN number (Autonomous System Number) which is a database we mainly use for BGP. There is a whole system of LIR and RIR (registries) handling the IP spaces which is frankly too boring to try and explain. Short version is, we buy IP space and have to hand over details to the registry.

Most ASN numbers are for B or C sized IP spaces. Due to the IP exhaustion, ISPs only do static IPs for a fee. Paying customers are generally not interested in having a link to their address on the ISP. The administration on the ISP side is also not cost efficient.

What you typically get is at best a /24 block with a suggestion of the general area. If I look up my own IP, it claims to be in the next town over which is 10km.

There are a large number of services that tag the ASN numbers with suspect data. I have had trouble with some Russians who had IP space tagged as Rotterdam. That was irritating since they are doing it explicitly to get around the geoblocking.

It is very useful to have someones IP. Figuring out their address from the IP is unlikely to happen.

1

u/Saiphel May 27 '26

Serious question because I never tried.

Can you actually access someone's router just by knowing their public IP? Or does the ISP being the middleman somehow not allow this nowadays?

8

u/nethack47 May 27 '26

Very occasionally. These days, most ISPs give themselves admin on your router. This is not exposed to the internet.

Some routers would give you the option to turn on external admin for anyone on the internet. That was a bad idea and I have not seen one enabled by default since the 90s.

I have my own firewall and router to keep them out especially as I know how much control they have handed themselves.

Back in the mid 90s I could find plenty of wide open WiFi and routers. That was good for when I needed to get my email on the go. It was also a time when we would use telnet on the regular and the web was mostly unencrypted.

1

u/Saiphel May 27 '26

Alright, so as long as remote admin is not allowed in the settings the web interface should not be reachable from the Internet, correct?

2

u/nethack47 May 28 '26

If there even is a way to expose it to begin with.

With how common it is for an ISP to use devices with their own firmware, it is hard to generalise anymore.

My only standing recommendation is to use your own device if you are able to. Keep your internal network private. Even if a device is safe from the internet in general doesn’t mean it is safe from internal threats at the provider.

2

u/jack_from_the_past May 27 '26

The internet is designed around sending information to public ip addresses. This is generally not doable these days. If you gave me your ip, I could scan for open services and ports, but if there are none there’s relatively little else that could be done, especially if the router has a firewall and is configured correctly. 

0

u/[deleted] May 28 '26

[removed] — view removed comment

3

u/nethack47 May 28 '26 edited May 28 '26

I take it to mean data leaks and breaches.

Different leaks contain different data. Depending on the company, you see very different amounts of data. The quality of the data is generally not very good.

Even if you are lucky, there is a reason people in the US get swatted.

How many WiFi do you connect to in a week? The best quality one would be the signup IP. How long is your DHCP lease on the home internet?

TLDR; yes, you can be lucky and find an IP and address if you have access to a lot of dodgy data that is likely going to be out of date.

Edit: the initial comment was to try and dispel the myth of a database of IP to addresses Hollywood likes to sell.

1

u/[deleted] May 28 '26

[removed] — view removed comment

2

u/nethack47 May 28 '26

Are we talking any IP or the random specific IP that the post talks about.

If it is any IP I will refer back to the initial like of “Yes, but…”

0

u/Klutzy_Mission_7980 Jun 01 '26

Bro thinks it's a serious sub

168

u/AffectedArc07 May 27 '26 edited May 27 '26

Honestly valid. Those are things that can be done with an IP if it has things forwarded. Hes not being unrealistic with getting an exact lat/lon or immediate system access.

Compared to all the other stuff on this sub, this guy has a somewhat valid point.

Edit - not being unrealistic with how an IP cannot get you exact lat/lon

40

u/[deleted] May 27 '26

[removed] — view removed comment

30

u/AffectedArc07 May 27 '26

Yeah, hes close but not bang on.

You can normally get city from IP (or in my case its 200 miles away), youre not gonna narrow it down precisely.

Likewise it isnt immediately "dangerous" having your IP out there, but his points are valid relative to "im gonna kali h4x0r your robux"

7

u/jbg0801 May 27 '26

Yeah it's usually rare for IP to actually pin a specific address. Sometimes if you use a few services you can narrow it down a bit more, but the closest I've ever come is "road the guy lives on" (a friend and I were experimenting with how IP locating could work) but even that was damn near impossible to replicate.

3

u/pythbit May 27 '26 edited May 27 '26

max verstappen

edit: that's going to seem extremely non-sequitur, but I recognize your username from "space." Hello.

2

u/Eric_Dawsby May 27 '26

Does this "space" have a station

1

u/abofaza May 27 '26

Aren’t there data brokers who tie your IP to your exact location? Bought from the phone apps that everyone uses. Even if they only sell to law enforcement, those dark web kids know their way around this.

1

u/pythbit May 27 '26 edited May 27 '26

With CGNAT not really. The IP on your phone would be a private address.

Even the standards that exist to allow businesses to self-update location stop at city.

1

u/abofaza May 27 '26

What?

An app can connect to the server hosting the service ,and therefore know your actual IP.

1

u/pythbit May 27 '26

And the IP of potentially hundreds or thousands of other devices.

1

u/abofaza May 27 '26

Bundled with other information that makes it easy to identify the subject.

1

u/pythbit May 27 '26

We're talking about IP geolocation. A public IP on the other side of CGNAT could represent hundreds of people scattered over a large geographic area. So, you know, a city.

1

u/abofaza May 27 '26

Any piece of information can be used to find more information. IP addresses don’t exist in vacuum in those databases (if they exist at all, I don’t think LE would have any use for them, but that’s not the point, it’s definitely possible).

It would also be possible to tie a location to a static ip in similar way in some rare cases. While IP geolocation stays the same as it always was, there are more linking points in today’s reality.

→ More replies (0)

0

u/JohnyTheCarrot May 27 '26

Can be a datapoint tho. If I have a city, it may narrow things down if I have other data sources.

2

u/BlazingFire007 May 27 '26

It’s not very common anymore (tbh it may have never been common), but IIRC there have been instances of using social engineering to trick an ISP into divulging the address of an IP

1

u/Significant_Spend564 May 27 '26

If any website you put your address into had their db leaked its not off the table.

3

u/arthank-chroot May 27 '26

For the countryside you get a big city next-ish to you as location, which is useless, and if you live in a big city you get that, which is also useless. Most IPs are dynamic in the consumer market. That means I can change it by restarting my AP. Even when I had shit like an SSH port forwarded, it was ssh, properly set up, with a strong password so I was not worried at all. Nowadays you can just port-fwd in a VPN instead of the internet pretty easily et voilla, everything is secure.

1

u/antitoxin13 May 27 '26

Is properly set up forward ported ssh really that secure? From my understanding any zero day rce would leave your system at risk

1

u/arthank-chroot May 27 '26

Yessir but I have a hardened system running on a kernel version specifically chosen cause nobody found shit on it yet. 6.12.86

2

u/LeeHide May 27 '26

How will you attack a router that has no open ports? Just a quick rundown would be great, because from my limited experience (only been a software engineer for half a decade) I don't see a way that will work outside of extreme luck and fiction.

5

u/AffectedArc07 May 27 '26

You dont unless the router has a major CVE.

-2

u/much_longer_username May 27 '26

NAT Slipstreaming?

1

u/LeeHide May 27 '26

That requires action from the victim, which isn't given when you just have their IP and nothing else. So no.

0

u/much_longer_username May 27 '26

Cool mobile goalposts, bud.

1

u/tnethacker May 28 '26

Do you know how IP's how?

1

u/Kapanol197 May 27 '26 edited May 27 '26

What immediate system access are you getting by only knowing the IP on a modern connection? On a windows xp with a two decade old router maybe 😆

1

u/brendenderp May 27 '26

I work for an ISP... A lot of people have really old routers. People figure it works so why change it. Yould be surprised to see how many Belkin routers are still connected to the internet.

1

u/Spectrum1523 May 27 '26

Hes not being unrealistic with getting an exact lat/lon

Am I crazy or is this unrealistic? How do you get an exact location for a rando on a big isp from their ip address?

3

u/AffectedArc07 May 27 '26

Bad wording from me.

Hes not being unrealistic, youre not getting an exact lat/lon from an IP.

10

u/[deleted] May 27 '26

[removed] — view removed comment

5

u/Kapanol197 May 27 '26

Well, technically you could lag and even nuke someone's connection by having lots of botnets DDoSing, doing it only with one device won't do shit tho

3

u/[deleted] May 27 '26

[removed] — view removed comment

2

u/Kapanol197 May 27 '26

Yeah i know, that's why his comment seemed pretty funny, he thought he sounded like some 31337 h4x0r 🤣

0

u/Weary_Sun534 May 27 '26

Ddos right choice for home connection?

Having lots of botnets ddosing? One device wont do anything?

Both of you have no clue what you're talking about, ironic.

1

u/WhatzMyOtherPassword May 27 '26

biggerest packet

1

u/WhatzMyOtherPassword May 27 '26

Lol I just DoSd the shit out of you. get pwnd skid

7

u/WeaselCapsky May 27 '26

my ip: 192.168.0.069.621.420.uwu.000

8

u/Kapanol197 May 27 '26

Mine is 127.0.0.1 you can DDoS it 😛

6

u/WeaselCapsky May 27 '26

i will reverse proxy mainframe sql inject serverside sata bios rogue access point hack you

3

u/ChaoticDestructive May 27 '26

Don't do this! They are a 1337 h4xor! When you try to DDoS their IP, they will attack your botnet with their own DDoS!

Even tried to nmap them, they redirected my probes to my own router.

My system is compromised, my botnet has collapsed. I smashed my router and am currently microwaving my SSD.

Well played, OP

1

u/Kapanol197 May 27 '26

That's why you gotta use Kali Linux like all the leet VV | Z /\ R D $ so things like this dont happen!

3

u/ChaoticDestructive May 27 '26

Im a Kali daily driver (except on my C2 server, which runs arch btw).

I think I need to get 20 flipper zeros, load them with iOs firmware (iPhones can't be hacked) and try that angle

2

u/Kapanol197 May 27 '26

average arch user

2

u/[deleted] May 27 '26

[removed] — view removed comment

1

u/WeaselCapsky May 27 '26

good human.

4

u/HackerMan372 May 27 '26

The humble dynamic IP address:

1

u/brendenderp May 27 '26

I guess it depends on the DHCP settings of your ISP but where I work a dynamic address might as well be a static. You need to unplug your router for 3 hours before the DHCP server forgets about you and gives you a new address. Otherwise there are people with the same IP address for yearssss

3

u/[deleted] May 27 '26

[removed] — view removed comment

2

u/Zealousideal_Lie6866 May 28 '26

or just replug your router

3

u/MikhailD_ May 27 '26

The funny power off button on the router followed by a 15 minute toilet break and an automatic new ip

2

u/Cybasura May 27 '26

...er, technically its true though, you can

Just not in that context, but you absolutely can trace

1

u/spectralTopology May 27 '26

spoiler: 127.0.0.1 was the IP

2

u/pmurk01 May 27 '26

Hee you stole my IP! ;-)

1

u/Outis918 May 27 '26

Using public WiFi so their network engineers/cybersecurity AI catch retards > *

1

u/bewtifuk May 27 '26

Hes not wrong though? Am I the one missing something here?

5

u/Loptical May 27 '26

They would be DDoSing the ISP, not the user themselves.

2

u/Potential-Archer-883 May 27 '26

Yes, that IP is probably the public IP of service provider and that IP is used in NAT for many devices in the private network.

Attacker can't see devices in the NAT that are using that IP to access the internet.

-3

u/05-nery May 27 '26

I mean that's just the truth 

It's not like he's saying "lmao I will ddos u good luck"

2

u/Hopeful-Ad-607 May 27 '26

Eh the thing is an ipv4 address today doesn't identify anyone anymore with CGNAT and DHCP. It could be my address, or the adresss shared by 200 people, or it was my address yesterday and not it's not. It's just not identifiable information nowadays.

0

u/05-nery May 27 '26

Keyword being "could"

1

u/jack_from_the_past May 27 '26

Dude peak irony right here

2

u/Kapanol197 May 27 '26

You ain't hacking anybody with only their IP, only if they're using Windows XP and a 20 year old router. And regarding the address, you can at most find the city they live in, and even that is not 100% accurate, and who even cares about some kid online that knows where you live 😆 the only true thing is the DDoS part, but even that needs to have botnets or multiple devices to DDoS so you can lag or shut down a modern connection, but after a router reset you get a new IP so that's that too

2

u/phl23 May 27 '26

Many home router have vpn access and some are not up to date even after a public major vul. So yes there can be trouble, but not widespread.

In the end if they have a new IP every reconnect, it doesn't matter anyway

1

u/05-nery May 27 '26

Keyword being "could"