You’re being watched! Some steps to find out who is behind an IP address on the internet…

I have recently been evaluating my website traffic in order to better serve visitors.

One line in the log evoked my curiosity. It was a URI from which someone visited my site:

http://www.google.com/search?hl=en&lr=&q=%22sean ervin%22 %2B greensboro&btnG=Search

What this means is that someone searched Google for: “sean ervin” greensboro and it led them to joehungry.com because of the Just Juan content on my site.

I IM’ed Sean and told him how interesting I thought this was. Who in the world is looking for him? We both were curious to know who is trying to find more about Sean on the web. But all we had was an IP address of the machine that apparently was used to do this (152.2.39.222). I was determined to find out who Sean’s secret admirer was! Let’s go!

  1. I needed a fully qualified domain name. Perhaps that would give me some useful information. From a shell, I ran nslookup 152.2.39.222 and got back rm524c.sowo.unc.edu. Wow! A UNC-CH computer. I guessed this from the IP address (152.2) but this pretty much confirmed it. So where is this computer? What is SOWO? I figured that was my next step. It is probably a department at UNC-CH.
  2. Onward to Google! A quick search at http://www.google.com/unc/ for “sowo” returned some useful hits. Looks like sowo is the abbreviation for School of Social Work. Yay! We’re getting somewhere.
  3. Oh! And look at this part of the fully qualified domain name: rm524c. Might that be Room 524C? If I was naming computers, that seems like a logical naming convention. Cool. So who is in room 524C? Was it that easy?
  4. I went to the School of Social Work homepage: http://ssw.unc.edu/, which I was in the Google hits from a previous step. Oh, hey, a site search at the bottom! How convenient. Let’s search for 524. Many times, they’ll list faculty, staff, and students with their office room numbers. Oh Boy!
  5. Hey, it worked! Sortof… Here was the result: http://search.atomz.com/search/?sp-q=524&submit=Search&sp-a=00050d5c-sp00000000 and of interest was this snippet of text in the results: “Chair of Doctoral Program Rick Barth in Room 524”. I IM’ed the name to Sean. He didn’t know him. Well it said Rick Barth is in room 524, and not 524C. Hmmm… Perhaps one of the doctoral students near his office? I clicked on the search result. Wait a minute! What’s this? A building map in pdf form at the top of the page? This is too easy.
  6. The building map: http://ssw.unc.edu/currentStudent/orientation/Florplan.pdf was pretty useful. I noticed that on the 5th floor, there was a computer lab. Could be any number of people. But likely someone in the department. Even more likely to be a student of staff. A faculty member would have just used the PC on their desk.
  7. Well, let’s find their students and staff lists then. Another visit to the School of Social Work homepage gave the option of seeing “Faculty and Staff”. There I found webpages listing Faculty, Staff, and Doctoral Students. Excellent!
  8. I sent Sean the link to the Students, but he didn’t recognize any names. Second list I sent was of staff: http://ssw.unc.edu/people/prosupp.htm and he recognized a name. A likely candidate!
  9. Krystie Grubb. He thinks this could be a person he used to manage in Greensboro, but not sure. No problem. Let’s find out more about Krystie. Her email address is kgrubb@email.unc.edu. That information is available from the list we were just looking at. Now here is where my knowledge of the computing environment at UNC-CH helped. I know that folks at UNC-CH are given webspace on the campus servers. You can access a person’s webspace by going to: http://www.unc.edu/~. My space is empty, but it is at, http://www.unc.edu/~jwaddell/, for example. So, I visited http://www.unc.edu/~kgrubb/ and, OH!….perfect!
  10. On Krystie Grubb’s UNC-CH homepage the first link was to her Resume. Would we find that this was the Krystie Grubb who worked with Sean in Greensboro? Reeee Rawwwww! 404 errors all over the place. Not a single URI worked on Krystie’s webpage.

So that’s as far as we got. I did a few Google searches for “Krystie Grubb” and found some interesting stuff, but nothing like a resume. That would have been the ultimate find on this expedition. Absolute proof! Until then, we may never know. Oh, and if that mysterious person out there is still looking for Sean, you can find him at skebrown.com. Adios!

2 Responses to “You’re being watched! Some steps to find out who is behind an IP address on the internet…”

  1. skebrown says:

    This was a fun exercise!

    Great post!

  2. […]

    Do you know who is behind the IP address that just found its way to your site? joehungry and I found some great information about who was looking for me and subsequently found there way to joeh […]

Leave a Reply