xoltaric
11-20-2003, 02:41 PM
Hi. I'm trying to see what a specific user did on my site. Going through the logs I was able to figure out his IP.
Doing a search of my logs for his IP I discovered more entries a few days later. What confused me was that according to the logs, he hadn't downloaded any HTML pages on the second day, just images. I looked at the log entry directly above these new items and found the expected HTML (well in this case CFM) page, only according to the logs, a different IP requested it. This single line was the only record of this IP at my site... the CFID and CFtoken verified that the requests came from the same computer.. so why the two IPs?
A reverse lookup of the IPs discovered that the IP used most often was in a block belonging to a corporate ISP, while the IP used only once was in a block owned by the company this guy works for.
Doing a search of my logs for his IP I discovered more entries a few days later. What confused me was that according to the logs, he hadn't downloaded any HTML pages on the second day, just images. I looked at the log entry directly above these new items and found the expected HTML (well in this case CFM) page, only according to the logs, a different IP requested it. This single line was the only record of this IP at my site... the CFID and CFtoken verified that the requests came from the same computer.. so why the two IPs?
A reverse lookup of the IPs discovered that the IP used most often was in a block belonging to a corporate ISP, while the IP used only once was in a block owned by the company this guy works for.