If a script kiddie can grab your IP address, they're one step closer to being a pain in your backside. More often than not they'll just use it to threaten you with empty promises of digital destruction; occasionally it'll be used for a bit of real world stalking via social engineering calls to your ISP, or pasting it into a DDoS program and watching the "fun" begin. It can also come in handy on the few "forgotten login" forms that sometimes request an IP address, but that's not a very common scenario.

Anyway, grabbing IP addresses. I noticed someone has come up with a clever way of doing it, and thought you might benefit from a big "avoid that site" warning. So here it is. The site to avoid is

and now we'll see why you should steer clear.

Click to Enlarge

Above, you can see the "ip detector" website. The attacker creates a username and enters their EMail address - when they hit Submit, they'll see a custom made URL with your unique ID number bolted onto the end.


You know what happens now, right? Yep, you guessed it. The attacker goes off, pimps their URL via IM, chatroom or forum and when the victim opens the URL (which is a fake "page is missing" message) have mail!


Every time someone hits your link, you'll receive one of the above. You can probably guess the content...


...whoops. You can see an example of how someone tried to grab IP addresses here, which is a forum thread discussing a page on Techdirt being owned by someone called Biohazard - who then went on to post this on the compromised page:


Click to Enlarge

You can see what he did there...

