help with sniffing

nulldata
by nulldata · 11 posts
6 years ago in Help & Support
Posted 6 years ago · Author
so there are a few "jokers" (AKA Xbox Modders) on VU who are starting beef with me and sniffed my IP out, so i got a new IP along with a VPN and i would like to know how i can sniff for an IP when on IMVU client to get back at them please help..

Thanks in advance :tlaconcerned:

WILL PAY :coin: 10,000cr :coin: who can help me
Posted 6 years ago
AnonReBoot wrote:
so there are a few "jokers" (AKA Xbox Modders) on VU who are starting beef with me and sniffed my IP out, so i got a new IP along with a VPN and i would like to know how i can sniff for an IP when on IMVU client to get back at them please help..Thanks in advanceWILL PAY 10,000cr who can help me





Just invite or ping him for a chat and while chat is ON open ‘Command Prompt‘ on your PC (Start >Run>cmd). CAUTION: before trying this make sure you close all the other tabs in your browser and only chat page is open. Also if possible delete all the history and cache from your browser !!! When command prompt opens Type the following command and hit Enter. netstat -an And you will get all established connections IP addresses there. Note down all the suspicious IP’s Tracing Location To do so we will be using IP tracer service. For this you can rely on http://www.ip-details.com Now you get ip address and you can locate the address of that person.

Read more: How to trace an ip address on IMVU - Can someone steal your imvu password with your ip address :: Zinf Questions and Answers at http://www.zinf.org/qna/How_to_trace_an ... tml#q80773
Posted 6 years ago
OK, I'm no expert but even if you're in a private chat with someone, it's not a peer-to-peer connection. Your PC is connected to an IMVU server and so is theirs. netstat will show the IP of the IMVU server you're connected to but I doubt seriously if IMVU's sandbox will let the other users IP address come through to you. The -af switch will show the domain names of the active connections so you can tell what's what.

There are a number of web statistics tools that will give you a users ip address but you have to somehow get them to visit the page you have the tool monitoring.

I don't think I've ever tried sniffing my connection while using the client but if I did it met with no success or I'd remember - lol. I still think all you will see is the traffic from the IMVU server to you, not anything from IMVU to the other user/users in the room. I could dust off my sniffer and try again if I get some extra time. (adds item to my todo list).
Posted 6 years ago
Soulljah wrote:
OK, I'm no expert but even if you're in a private chat with someone, it's not a peer-to-peer connection. Your PC is connected to an IMVU server and so is theirs. netstat will show the IP of the IMVU server you're connected to


Yeah, that's what I was thinking too.
Posted 6 years ago · Author
Soulljah wrote:
OK, I'm no expert but even if you're in a private chat with someone, it's not a peer-to-peer connection. Your PC is connected to an IMVU server and so is theirs. netstat will show the IP of the IMVU server you're connected to but I doubt seriously if IMVU's sandbox will let the other users IP address come through to you. The -af switch will show the domain names of the active connections so you can tell what's what.There are a number of web statistics tools that will give you a users ip address but you have to somehow get them to visit the page you have the tool monitoring.I don't think I've ever tried sniffing my connection while using the client but if I did it met with no success or I'd remember - lol. I still think all you will see is the traffic from the IMVU server to you, not anything from IMVU to the other user/users in the room. I could dust off my sniffer and try again if I get some extra time. (adds item to my todo list).



So something like wireshark, or cain and able wont help in this matter? bc when he got my IP i was in a room with him and a few others , and i didnt click no links or nothing :tlatakenote:
Posted 6 years ago
I wonder how do you know the IP address that he got is yours? Did u just take him for his words or did he show you the IP and you compared the IP with yours by going to a website that can check your IP address such as cmyip.com?

I mean we need to check fact for fact first before taking someone's word for it, just saying.
Posted 6 years ago · Author
buddybud wrote:
I wonder how do you know the IP address that he got is yours? Did u just take him for his words or did he show you the IP and you compared the IP with yours by going to a website that can check your IP address such as cmyip.com?I mean we need to check fact for fact first before taking someone's word for it, just saying.


yes it was my ip he sent it to me in a DM.
Posted 6 years ago
AnonReBoot wrote:
So something like wireshark, or cain and able wont help in this matter? bc when he got my IP i was in a room with him and a few others , and i didnt click no links or nothing


And you never visited his IMVU homepage? Or the homepage of any of the other 'jokers'. You still don't know when he got your IP only when he told you he had it. The amount of data wireshark or any other sniffer collects is enormous. Nobody is going to capture data from a room, isolate your packets from everyone elses, and pinpoint your IP in a couple of minutes.

I just got my sniffer (similar to wireshark) updated and reinstalled and will be capturing some traffic today to see what I can see. I'll post results later.

If someone really got your IP from a room chat, then he has a tool I want.

-- Tue Apr 03, 2018 9:07 am --

OK, results. I won't post the complete analysis 'cause I don't want to spam the thread but if anybody wants it, I can PM you the notes. First the test conditions. I rebooted my PC, ran CCleaner for cookies, started my VPN and only opened one webpage to My IMVU and started the client (IMVULite). After establishing a private chat with a friend, I ran netstat -an, netstat -af and started my sniffer capturing 60,000 packets. Here some general info that everyone might find interesting:
1) Even with so little going on, I had 35 active TCP/IP connections!
2) 5 of those were cookies from Amazon, Microsoft, Google and a web security firm named CloudFlare - despite CCleaner. Unfortunately, the payload did not indicate who CloudFlare set the cookies for.
3) Amazon, Google, Facebook and YouTube all used IMVU apis to get my User Name and Customer ID over other (non-cookie) connections. Google, FB and YouTube at least encrypted them, Amazon gets them in clear text. :/
4) IMVU uses Akamai Technologies for hosting.
5) IMVU's api server also exchanges User Name and CID in the clear. :/
6) IMPORTANT! The IMVU Message Queue packets (chatting and realtime web page, avi card, etc. updates) were all encrypted after the initial handshake with the client. It may just be gzip which only compresses the data for performance purposes or it may be real encryption. I don't have the skills to tell.
Most importantly I didn't find any active IP connections to my chat partner. No searchable info (i.e. sent in clear text) in any packet payload regarding their IP, name, or CID, all of which I know and could search for. So again, I don't know how they got your IP but pretty sure it wasn't by sniffing a chat or using netstat.
Posted 6 years ago · Author
@Soulljah


Thanks for the help imma just assume they got my Skype form a friend of mine and just resolved my skype user thats the only think i can think off that they can get my ip that simple :tla9:
Posted 6 years ago
Nobody is in trouble or anything but from now on, please don't quote entire posts in your reply. It causes too much clutter to scroll through.

Quote only the neccassary parts or if you just want to show you're replying to someone specific, use the tag bbcode:

Code
[tag]Mafia Name[/tag]


This will not only display their name in your reply but will also send them a PM telling them you mentioned them in a post.

All that said, carry on... :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Sign in

Already have an account? Sign in here

SIGN IN NOW

Create an account

Sign up for a new account in our community. It's easy!

REGISTER A NEW ACCOUNT