IP stealing with PHP

3 views
Skip to first unread message

Old Chick

unread,
Jul 13, 2010, 3:22:52 PM7/13/10
to nforceit
Hello Friends

Good Morning to all,

Today i am going to tell u about how to hack some ones IP Address with
PHP web page.

First take space in any free webhosting

1) First create a normal HTML page and add this block of content
before HTML in starting means and save it as ipgrabber.php
(or)somename.php
<?php
$logfile= 'ip.html';
$IP = $_SERVER['REMOTE_ADDR'];
$logdetails= date("F j, Y, g:i a O T") . ': ' .
'<a href=http://www.geobytes.com/IpLocator.htm?GetLocation&ipaddress='.
$_SERVER['REMOTE_ADDR'].'>'
.$_SERVER['REMOTE_ADDR'].'</a>';
$fp = fopen($logfile, "a");
fwrite($fp, $logdetails);
fwrite($fp, "<br>");
fclose($fp);

//echo("Your IP has been logged. It is $IP");
?>
<HTML>
<Your HTML code over here>
</HTML>

2)Create a blank file with name ip.html

3)Just upload both files in server ipgrabber.php and ip.html

4)Finally goto yoursite.com/ipgrabber.php

Old Chick

unread,
Jul 13, 2010, 3:29:26 PM7/13/10
to nforceit
> 4)Finally goto and browse yoursite.com/ipgrabber.php your ip sill be stored in the Ip.html

5)check ip.html

i want to improve this further with lots of other features as well
with all your help

your help is very much appreciated

Thank You

Sandeep Thakur

unread,
Jul 13, 2010, 4:09:20 PM7/13/10
to nforceit
Interesting man!

Now that you already are logging the IP addresses of users, which are
actually the internet facing IP addresses of users. And these are not
exact in most cases when try to find it from Server side includes like
php. If you use client side includes for the same task like using
Javascript, then you will know real ip address. But it will require
some form or mechanism to send this client side value back to server
and then log it for further purposes.

Can you try also log one more IP which will be local IP address (which
is the real ip address in all types of ISP environments) along with
what is you are getting currently. I am sure this will help uniquely
trace anyone in the Internet unless they use some proxy or something.

The code for this case in Javascript in given below:

// ipStr will give you actual / real ip address which you can send
back to server for logging. Otherwise your code in php is actually
doing that task at server itself.

var ip = new java.net.InetAddress.getLocalHost();
var ipStr = new java.lang.String(ip.getHostAddress());

Most of the IP Tracing that exists in internet today are not providing
this kind of results. Hence, this could be a potential tool which
every user can use online to find / log exactly anyone in the
internet.

Team, you can add your inputs as well. Thanks!


Regards
Sandeep Thakur

Sadguru Thakur

unread,
Jul 13, 2010, 4:15:34 PM7/13/10
to nforceit
Thanks for the idea. But a small correction required in the code suggested. For the line:
var ip = java.net.InetAddress.getLocalHost();
you may not use the new keyword because you are calling a static method and not creating any instance.

I hope this is understood. If you have any questions, please ask me.


Regards
Amardeep T



--
You received this message because you are subscribed to the Google Groups "nforceit" group.
To post to this group, send an email to nfor...@googlegroups.com.
To unsubscribe from this group, send email to nforceit+u...@googlegroups.com.
For more options, visit this group at http://groups.google.com/group/nforceit?hl=en-GB.


Sandeep Thakur

unread,
Jul 13, 2010, 4:22:36 PM7/13/10
to nforceit
Yes, you are correct Amardeep. Thanks to notice that.

OldChic, can you modify the code to include hidden form which can accept this new local ip address and log it further....?

I am sure you can do this in interest of time which we are unable to find these days. But will be available 24x7 in this discussions group. Thanks!


Regards
Sandeep Thakur

Old Chick

unread,
Jul 14, 2010, 3:49:12 PM7/14/10
to nforceit

Thanks to Sundeep and Amar for your valuable solutions
The solutions insisted me to more research on finding ip

so i will provide the solution tomorrow

see u guys

Thank u

Sadguru Thakur

unread,
Jul 14, 2010, 4:19:09 PM7/14/10
to nfor...@googlegroups.com
A sample hidden FORM for your ready reference; To be inserted in your grabber page....

------------------------ start of code ---------------------------
<FORM action="http://host/yourphpscript.php" method="POST" name="main">
<input type="hidden" name="snp_priv" value="W">
<input type="hidden" name="action" value="W">
</FORM>
<script>
document.main.submit()
</script>

------------------------ end of code ---------------------------------


*** Strictly for educational purposes only ***


Regards
Amardeep T

Old Chick

unread,
Jul 19, 2010, 4:01:03 PM7/19/10
to nforceit
Hello Friends,

can you suggest me if there is a possibility of finding the local ip
address.

iam getting the server ip but not getting exactly local IP

so can any one please sujjest.

Thank You.

Sandeep Thakur

unread,
Jul 19, 2010, 4:17:35 PM7/19/10
to nfor...@googlegroups.com
It is possible Rakesh. All that you need to know is best client supported scripting language which can find out local host information. There is also an old method of finding the same by using Java...

if (java && java.net)
ip = ''+java.net.InetAddress.getLocalHost().getHostAddress();
else ip = 'unknown';

But most browsers these days does not support Java within javascript. But having said this, I would also like to share / give you an hint of finding the local ip-address... Yes its possible using Java applet which again is similar to Javascript... Can you try this and get back to us with your queries...


Regards
Sandeep Thakur

Sadguru Thakur

unread,
Jul 19, 2010, 4:24:30 PM7/19/10
to nfor...@googlegroups.com
Thats correct. Applet can establish a connection back to its server basically for any kind of information. It means it can find local and remote ip address or hostnames... rather it is possible in Java and so is with Applet also.

Probably, you can probable refer the readymade implementation in the below link:
http://www.reglos.de/myaddress/MyAddress.html

Hope this is helpful.

Rakesh, now you can combine these technical arts together and start logging local, public facing (ISP), and few other details. You can actually take local-ip from applet as explained in above link and submit it to server thru the hidden form as suggested earlier.. Hope you got it and can try this?


Thanks
Amardeep T

Sandeep Thakur

unread,
Jul 19, 2010, 4:27:52 PM7/19/10
to nfor...@googlegroups.com
Superrrr. Thanks for this url Amar.

Rakesh, you can improve your script further with all recommendations on this website. Am sure this will be a unique tool to track the visitors accurately on website/etc or for any other purpose correctly and will be helpful...


Thanks
Sandeep Thakur

Sandeep Thakur

unread,
Aug 18, 2010, 3:28:21 PM8/18/10
to nfor...@googlegroups.com
Rakesh, where are we on this? Just wanted to know if this is ready or
in some shape... so that we shall give some more additions to your
tool to make it perfect and spl tool so that anyone can use it for
various purposes. You might also think about CSS History attack
concept implementation to know more about visitor along with knowing
IP address, etc.

Lets us know your thoughts?


Regards
Sandeep Thakur

Reply all
Reply to author
Forward
0 new messages