Tracking IP through a socks5 proxy + RDP ?
- by piro
Hi all.
We were having some issues at work until we found that we are being attacked almost every day. The attacker seems pretty smart - at first he was always using proxy to hide his IP. With scanning I found that they were socks 5 proxy. The last week we had 11 attacks and every time i found the ip i scanned it with nmap. I found that ALL of the 11 different ip addresses were RDP (port 3389 open, and accept rdp connections, checked by myself on ALL of them).
So here follow the questions:
1. Can we trace his real IP back through a socks5 proxy ?
2. Can we trace him if he is using some RDP server to hide his ip ?
Please do not answer like "Call the owner of the proxy server/RDP..." etc. we already tried it and it didn't work, that's why I am writing here.
Thank you very much.