# Identifying IP Address

**URL:** <https://boards.straightdope.com/t/identifying-ip-address/304282>\
**Category:** Factual Questions\
**Created:** [May 17, 2005, 7:02pm UTC](https://boards.straightdope.com/t/identifying-ip-address/304282 "2005-05-17T19:02:32Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![guizot](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/guizot/32/3636_2.png) [@guizot](https://boards.straightdope.com/u/guizot)\
**Post date:** [May 17, 2005, 7:02pm UTC](https://boards.straightdope.com/t/identifying-ip-address/304282/1 "2005-05-17T19:02:32Z")

</div>

My firewall occasionally says that another computer is scanning my computer’s ports, and that it’s been blocked. It gives the IP address. How can I find out who this is without going to that address?

---

<div class="post-metadata">

**Author:** ![MEBuckner](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mebuckner/32/2896_2.png) [@MEBuckner](https://boards.straightdope.com/u/MEBuckner)\
**Post date:** [May 17, 2005, 7:04pm UTC](https://boards.straightdope.com/t/identifying-ip-address/304282/2 "2005-05-17T19:04:16Z")

</div>

You can find out some information about it by entering it into the “Search WHOIS” box in the upper right area of [this page](http://www.arin.net/).

---

<div class="post-metadata">

**Author:** ![guizot](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/guizot/32/3636_2.png) [@guizot](https://boards.straightdope.com/u/guizot)\
**Post date:** [May 17, 2005, 7:05pm UTC](https://boards.straightdope.com/t/identifying-ip-address/304282/3 "2005-05-17T19:05:04Z")

</div>

Thank you.

---

<div class="post-metadata">

**Author:** ![ComeToTheDarkSideWeHaveCookies](https://avatars.discourse-cdn.com/v4/letter/c/e9bcb4/32.png) [@ComeToTheDarkSideWeHaveCookies](https://boards.straightdope.com/u/ComeToTheDarkSideWeHaveCookies)\
**Post date:** [May 17, 2005, 7:51pm UTC](https://boards.straightdope.com/t/identifying-ip-address/304282/4 "2005-05-17T19:51:12Z")

</div>

Doing your own forensics on things like firewall traffic can be quite the fulfilling and satisfying hobby. I applaud anyone wanting to take that geeky plunge, the water is lovely.

However, there are a signifigant amount of folks for whom the idea of determining if the firewall alert is for “acceptable” or “hostile” activity, looking up IP ownership, and filing some sort of formal complaint…prompts projectile vomiting.

For these folks (as well as the avid geeky hobbiest who might want a few extra hours to devote to things like grocery shopping, changing the oil in the car, or perhaps spending time with those strange people who share your house and keep calling you odd names like “Honey”, “Mom” or “Dad”)…I highly recommend signing up for MyNetWatchman ([http://www.mynetwatchman.com/](http://www.mynetwatchman.com/)).

Simply put, you download their software, tell the software where your firewall logs are located, decide how much visibility you want to have into the automation, and…_magical chimes_…the service collects, analyzes, prioritizes, and reports your firewall traffic for you to the appropriate parties who A) care and B) can do something about any malicious activity.

Good stuff.
