Hacker News new | ask | show | jobs
by spyne-02139 5748 days ago
post the email headers here
3 comments

Or 4chan. It seems those people love challenges like this.
Delivered-To: shereef@gmail.com Received: by 10.227.137.69 with SMTP id v5cs104210wbt; Sat, 18 Sep 2010 18:42:06 -0700 (PDT) Return-Path: <101badkarma@gmail.com> Received-SPF: pass (google.com: domain of 101badkarma@gmail.com designates 10.142.223.11 as permitted sender) client-ip=10.142.223.11; Authentication-Results: mr.google.com; spf=pass (google.com: domain of 101badkarma@gmail.com designates 10.142.223.11 as permitted sender) smtp.mail=101badkarma@gmail.com; dkim=pass header.i=101badkarma@gmail.com Received: from mr.google.com ([10.142.223.11]) by 10.142.223.11 with SMTP id v11mr6012112wfg.29.1284860525531 (num_hops = 1); Sat, 18 Sep 2010 18:42:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:received:date:message-id :subject:from:to:content-type; bh=En3bZiL4+B5vTtybnZXiAYgxVH8KE7aSzQ8trXFJhfw=; b=b0mf+OtiHbF5VdsI9H27MN7Tmwz6NLqkFU/1fPmYNqbBNOR7kkXv0OrJsD3zIbZ4Js i6eaN1cBbq5DEDjxxJIqhwPBaJw6qUAJkQvFXeg9F/afpS6e3/jyfBbthgcXCEKxFfg+ vwaTfaiQeFFyXHTI1CG5XZLCICl2L7LXVH/tA= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:date:message-id:subject:from:to:content-type; b=aZps057Ba5cXMeIEOROw7bo/ZxucfJyDaLxN0F3nepTGQYtaUFtpA+H1irq3s5CfeE A0z0zWtaKFAVe3K6VJibIRleRkCaIy8WDKkoWMUTze1xQcSWphWiiDK8yixD989a8LRW unv0IRELrI4cauF32fgTvT4wW3Sa+leUuv20I= MIME-Version: 1.0 Received: by 10.142.223.11 with SMTP id v11mr6012112wfg.29.1284860525521; Sat, 18 Sep 2010 18:42:05 -0700 (PDT) Received: by 10.142.135.13 with HTTP; Sat, 18 Sep 2010 18:42:05 -0700 (PDT) Date: Sat, 18 Sep 2010 18:42:05 -0700 Message-ID: <AANLkTi=ek0sq9johN8AYFjQQXpg0kvGtE5ZXn0MZ=zU0@mail.gmail.com> Subject: Stolen Laptop From: karma bad <101badkarma@gmail.com> To: shereef@gmail.com Content-Type: multipart/alternative; boundary=000e0cd17e7635ad30049092e752

--000e0cd17e7635ad30049092e752 Content-Type: text/plain; charset=ISO-8859-1

I don't know much when it comes to ips, i.e., I can't tell whether that is a shared ip, or otherwise.

Nonetheless, a quick search reveals this individual (http://www.scamwarners.com/forum/viewtopic.php?f=34&p=32...) used/had that ip 3 months ago. (S)he appears to be a security specialist, which goes with the impression I got from the email.

You're right, you don't know much about IP addresses. The entire 10.x.x.x block was reserved long ago for use on private networks, it's not routed anywhere on the internet. This RFC from 1996 describing best practices for their use is still accurate: http://tools.ietf.org/html/rfc1918

All of those addresses in the header posted are hosts within one of Google's networks. The same address is likely in use on other such networks.

Now, now. Let's not go vigilante. There's a site dedicated to that stuff if the OP is interested. It's called Reddit.

Edit: By the downvotes, I see that apparently HN is not above internet mob justice. My mistake, carry on.

I can tell you first hand the police don't have the manpower or knowhow to track people on the internet. They're good but they need help.
It's only vigilante justice if someone illegally punishes the criminal. Helping the police locate a suspect is called "being a good citizen".