How do I find an attackers IP from a DDOS or DoS

HeyItsMike

Reputable
Dec 29, 2014
1
0
4,510
Is there any way that I can find an attackers IP during the time that they are DDoS'ing or DoS'ing me. I believe right now that it is just a kid with a simple DoS but anyways is there anyway I can find his IP even if he is behind a VPN?
 
Solution
In the case of DDOS (Distributed DOS), you're being attacked by many computers (whose owners have no idea they're part of a botnet), so even if you get the IP address, it won't help (e.g. you're located in USA, and you see an IP address located in Asia..)
How do you know you were DDoS'ed? If you are seeing massive requests to your Routers WAN, then you should be able to see the source(IP) of these requests.

If they are behind a vpn I don't think it's possible. Also make sure your router/mfd(Multi-function device) is set to ignore anonymous requests/pings on the WAN port.
 

casper1973

Distinguished
Dec 30, 2012
942
0
19,360
Depends on what router/firewall you have. Most decent routers will keep logs of incoming requests but you sometimes need to enable this in settings.

Once you have the logs enabled its a case of studying them during the period you believe the attack occurred.


Unfortunately, it's more than likely they will masking their IP in some way (eg. VPN)
 
In the case of DDOS (Distributed DOS), you're being attacked by many computers (whose owners have no idea they're part of a botnet), so even if you get the IP address, it won't help (e.g. you're located in USA, and you see an IP address located in Asia..)
 
Solution