Recapturing the charm of Dad’s Lionel train

I unboxed Dad’s old Lionel train Monday night. They don’t make them like that anymore.

Dad’s train led a rough life. My investigative reporting skills tell me he got the train sometime between 1949 and 1952, and then sometime after 1953 he got a new locomotive and cars. And then sometime in the 1960s, the trains ended up in a box. I remember him telling me it came out a few times in the 1970s for Christmas, but most of my memories of Dad’s train are four big pieces of plywood with rusty track mounted on it, sitting in the garage next to a stack of repurposed liquor boxes containing train parts.

Read more

Easy and secure remote Linux/Unix file transfers with SCP

Sometimes you need to transfer files between Linux boxes, or between a Linux box and some other box, and setting up Samba or some other form of network file system may not be practical (maybe you only need to transfer a couple of files, or maybe it’s just a one-time thing) or possible (maybe there’s a firewall involved).
Well, you should already have SSH installed on your Linux boxes so you can remotely log in and administer them. On Debian, apt-get install ssh sshd. If you’re running distro based on Red Hat or UnitedLinux, you may have a little investigative work to do. (I’d help you, but I haven’t run anything but Debian for 2 or 3 years.)

The cool thing about SSH is that it not only does remote login, but it will also do remote file transfer. And unlike FTP, you don’t have to stumble around with a clumsy interface.

If you want to transfer files from a Windows box, just install PuTTY. I just downloaded the 240K PSCP.EXE file and copied it into my Windows directory. That way I don’t have to mess with paths, and it’s always available. Make sure you’re downloading the right version for your CPU. The Windows NT Alpha version won’t run on your Intel/AMD/VIA CPU. Incidentally, Putty.exe is a very good Telnet/SSH client and a must-have if you’re ever connecting remotely to Unix/Linux machines from Windows.

SSH includes a command called SCP. SCP works almost like the standard Unix CP command. All you to do access a remote file is append a username, followed by the @ sign, and the IP address of the remote server. SCP will then prompt you for a password.

Let’s say I want to move a file from my Linux workstation to my webserver:

scp logo.jpg root@192.168.1.2:/var/www/images

SCP will prompt me for my password. After I enter it, it’ll copy the file, including a nice progress bar and an ETA.

On a Windows machine with PuTTY installed, simply substitute the command pscp for scp.

I can copy the other way too:

scp root@192.168.1.2:/var/www/index.php .

This command will grab a file from my webserver and drop it in the current working directory.

To speed up the transfers, add the -C switch, which turns on compression.

SCP is more secure than any other means of file transfer, it’s probably easier (since you already need SSH anyway), and since it’ll do data compression, it’s probably faster too.

Preserving those new (and old) holiday memories

Sorry, I never got around to those promised posts because, well, I’ve become a genealogy addict. But don’t you worry, this post is relevant even to people who are sick of reading about genealogy.
Mom and I were going through some old photo albums, and some of the photographs were in pretty bad shape. For all the talk about concerns over how long inkjet prints of digital pictures might last, some of Mom’s 30-year-old prints are, well, fading fast. Meanwhile, Mom has some prints that were taken 30 years ago that look like they could have been processed yesterday, except for the clothes the people were wearing.

I remember almost 15 years ago, when a neighbor’s house burned, going through their rescued photo albums, opening up the drenched pages, taking out whatever photos would come out in one piece, and putting them on towels scattered about the house to dry. I noticed that Polaroids are very difficult to get remove intact from sticky album pages, even under ideal conditions. Well, now I wonder if anyone pays attention to the acid content in those album pages and what else might contribute to pictures deterriorating.

But I’m not going to spend too much time thinking about that (why not leave that to the infamous self-proclaimed aristocrat and scientist?) because there’s an easy solution.

Scan those bad boys.

Most people have mountains of photographs, so it’ll take a while, but if you set out to scan a page a day, or a few pages a week on Saturdays and Sundays, you’ll eventually get through them. Burn them to a quality CD–I know among the name-brand discs you find in stores, the most consistent performer you’ll find is Kodak. If you buy in bulk, your best bet is either Mitsui or Taiyo Yuden, which are the two brands that CD duplicators most frequently use. The estimated lifespan under reasonable conditions for a high-quality CD-R is around 100 years. Some of my cheap house-brand CD-Rs haven’t lasted two years. So buy good stuff, and store the discs at room temperature. Don’t put them in the attic unless they’re full of pictures of former significant others whom you wish you’d never met. Remember the basic scientific principle that raising the temperature 10 degrees doubles the speed of a chemical reaction, so in theory, raising the temperature 10 degrees halves life expectancy. Storing your CD-Rs in a closed box in the basement, assuming it’s not terribly humid down there (40% relative humidity is optimal, according to Kodak), would be a good idea.

Actually, that same principle would be just as true for your prints as well.

Anyway, what do you do when the prints have already started to fade? Scan them anyway. Sometimes the scan ends up looking better than the original. If not, then try turning them into B&W pictures. Use your imaging software to convert it to greyscale, then play with the brightness and contrast. You’ll lose the color, but you might very well save the print. In the case of some of the old pictures of me, it’ll be harder to tell that I had blonde hair when I was really young, but it’ll at least be possible to tell what I looked like.

If you don’t have a scanner or you’re dissatisfied with the speed or quality of your existing scanner, I can recommend Canon’s LiDE series. They’re inexpensive and offer a very nice combination of speed and image quality. Most of them get their power from the USB port, which saves you a power outlet. And they’re small and light enough that they can fit into a laptop bag, making it possible to take a scanner and laptop along with you when you visit family and scan some old photos.

Getting those photos into digital form gives you other advantages as well. Some imaging software allows you to add captions or descriptions to the photos. If you’re Linux-savvy, you can set up a nice family website using one of the 12 bazillion gallery programs out there. You can keep it on your local LAN if you don’t want that stuff on the public Internet–you and your family can still enjoy punching through pictures on a strategically placed computer the same way you flip through old photo albums. If you’ve got a nice color printer, you can make as many reprints as you want, and if they fade, you can always just print them again. And while you’re burning CDs, you can burn an extra copy or two and keep them in someone else’s basement. If disaster strikes, insurance can replace most material items, but not the one-of-a-kinds like your photographs. Fortunately it’s easy to ensure they’re no longer one-of-a-kinds.

Yet another genealogy tip

One more tip for those of you looking to get started in genealogy: Don’t forget the library. You know, that place with tons of books in it that you don’t want to set foot in since you discovered the Internet. The Internet’s less reliable and the information on it definitely leans towards some subjects more than others, but Google’s always open and it’s faster to turn on the computer than it is to hop in the car and drive.
The St. Louis County Library, for example, offers access to U.S. Census data and historical biographies through HeritageQuest.com and access to numerous newspaper archives. It’s arguably as good as the $80/yearly packages offered by a lot of online services, and I’m already paying for it. Some of the newspaper archives are only available inside the library from its own computers, but there’s plenty of data available from home using your library card.

It’s worth a look to see what your local library offers.

I’m going to try to post again later today, and maybe tomorrow before I hit the road and head west.

This is still a blog

A year, or maybe two years ago, I wrote a piece called “This is a blog” in response to an overly full-of-himself author who said that serious professionals don’t blog. It infuriated some people and got me kicked off the daynotes.com web page. I don’t have anything like that to lose this time around, so I don’t approach the topic with the same kind of eagerness–you’re always more eager when you know someone’s going to be offended and throw a temper tantrum–but since everyone and his uncle seems to be writing about John C. Dvorak’s current PC magazine column, Co-opting the future, I might as well weigh in, since it’s the in thing to do, and disagree with the majority knee-jerk reaction, since that isn’t the in thing to do. But I won’t do it to be counterculture. No, I’ll disagree with the majority reaction because the majority reaction is wrong.

Yes, I find it funny that the guy who was recommending novelty domain names as Christmas presents back when a domain name still cost $99 a year is today opposed to blogs. What else is someone going to do with a personalized domain name? I’ll tell you what I’d do if someone gave me the davefarquhar.com domain–I’d run a mail server on it and I’d hang my blog off it. Dvorak would run a mail server off it and post some recipes on it and some pictures of his pets. But my site would be more useful–at least blogging software provides a search engine so you can find the stuff. Isn’t it tacky to tell people to go to Google and type what they’re looking for, followed by site:yourdomainnamehere.com?

But unlike the vigilante masses, I don’t take issue with the majority of what Dvorak says. So he cites a paper that says the majority of blogs get abandoned. The blogosphere goes nuts. Well, I’m sorry, folks, but Dvorak’s right. Go to any public blogging community and start navigating random sites, and you’re going to find a lot of abandonware. It’s like any other hobby. It’s great when the novelty is new. But eventually the newness fades away. Some people abandon their blogs for a while, for various reasons, then come back. Hey, I posted as much in the months of September and October as I used to post in a week. It happens. I came back because I love writing. Some people find they don’t love writing. Some people find they love writing but they run out of things to say. It happens. Large numbers of people trying it and deciding they don’t like it doesn’t invalidate it. How many millions of cameras sit in closets, only to be taken out during birthdays and holidays, if then? Does that somehow invalidate photography?

Then Dvorak says the people who stick with blogging are professional writers. Interestingly, the people rebutting Dvorak bring up the blogs written by–guess who?–professional writers. Now I don’t see how that invalidates Dvorak’s point that the longest lasting, most popular blogs tend to be written by people who do it professionally. I think it’s obvious. If you’re going to write professionally, you have to love it. And if you love writing, you’re more likely to blog.

In other news, computer professionals are more likely than others to build their own computers, dogs are more likely to bark than cats, the sky is blue, and if there’s snow on the ground it’s probably cold outside.

The really incendiary statement Dvorak quotes is that the majority of blogs have an audience of about 12 people. Sometimes reality hurts. I remember checking my logs in my early days and being shocked when I had 40 visitors. Then I was shocked when I found out some people looked up to me because I had 40 visitors. I thought I was the only small-market guy.

Eventually, one of three things happens to every small-audience blogger. Some get frustrated and quit. Others toil on in obscurity. Still others one way or another stumble onto something that people like and they grow their audience.

Today, my audience is closer to 12 hundred people. That doesn’t make me a superstar, but it’s not bad. Some people I remember celebrating breaking 20 readers a day five years ago aren’t doing it anymore. Others are, and they probably get 1200 people a day too. Or more.

I didn’t like Dvorak’s tone, but Dvorak will be Dvorak. I didn’t like Dvorak’s tone when he wrote about OS/2 either, and I think Dvorak’s personal crusade against the caps lock key is idiotic and annoying. He needs to just download a utility that remaps it to a control key and shut up. Those of us who really know how to type will continue to use it when we need it. So Dvorak doesn’t like blogs either. If I only ever read people who agree with me, I wouldn’t ever read.

The only thing I really disagreed with was Dvorak’s assertion that big media is taking over the blogs. Yes, big media is blogging. But the little guys will always outnumber big media. There’ll always be professional writers who blog on their own time to keep sharp or to experiment. There’ll be part-time pros like me who don’t like big media and don’t like most editors–well, I can name four editors I worked with who I liked–who blog because it’s a way to write and stay in touch with the craft and be true to one’s self. There’ll be up-and-comers who are in high school or college and decide to start blogging as part of the process of finding one’s self. There’ll be people who do it just as a hobby.

And guess what? Google starts out with no assumptions. It treats all links the same. That’s why little guys like me can get 1,200 hits a day.

And next week Dvorak will be off on another crusade. There’s about a 50% chance of him being right. I’ve known that since I started reading the guy a decade ago.

Getting started in Genealogy

I’ll admit it. I’m not ashamed of it. I’m a johnny-come-lately to the genealogy game. My computer can tell you how I’m related to more than 1,200 different people. And I just started last week.
I’ve accumulated more names than my mom did in years of research, working the old-fashioned way in the 1970s, searching libraries, museums, LDS records, and graveyards.

So how’d I do it?

Talking about Mom’s side of the family is cheating, because she can easily trace her ancestry to pre-Civil War days. Dad’s side of the family was the challenge, because his parents never talked about their roots (my grandmother actually told my mom to quit nosing around in the past and spend time with her two young kids instead–advice that I, as one of those two kids, disagree with, but it’s too late now).

Here’s what I did. I knew that my great great grandfather was named Isaac Proctor Farquhar (I didn’t know if the middle name was spelled “Proctor” or “Procter”), that he was a doctor, and that he lived in Ohio. I literally punched “Dr. Isaac Proctor Farquhar Ohio” into Google to see what came up. What came up was a family tree tracing my ancestry back to 1729. I verified it because I knew the names of my great grandfather and grandfather.

A better approach is to visit a pure genealogy search site, such as ancestry.com or the Mormons’ familysearch.org and punch in the names of any deceased relatives you can think of. The further back they are in the past, the better. The names of living relatives aren’t very useful, since people almost always strip out the names of any living people from their online records due to privacy concerns.

Once you’re reasonably certain you’ve found a relative, enter whatever you can find into your computer. Family Tree Maker is a good piece of software for tracking your roots, and it’s not terribly expensive. Several sites offer free genealogy software. I haven’t looked at any of it. There’s little risk in trying it though–virtually every genealogy program can import and export data in GEDCOM file format. A number of free Linux genealogy programs are available too–just search Freshmeat.

I need to stress entering anything you can find. Often I find incomplete genealogies online. I’ll find a record for a great great great grandfather that lists two children and a birthplace. If I’ve previously entered all available data and I know my great great great grandfather had 10 kids, including the two on that genealogy I just found, and the birthdates and birthplaces and spouses’ names all match, then I can be reasonably certain that I’ve got the right ancestor and I can see where that trail leads me. It’s more fun to track direct ancestors and see how far back into the past you can go, but you need aunts’ and uncles’ and cousins’ names to prove relations sometimes. Besides, sometimes you find a distant cousin who married someone interesting.

If you don’t find anything, talk to your living family members. Ask if they can remember any relatives’ names, birthplaces, and anything else about them. I only know about Isaac Proctor Farquhar because of some conversations I had with my dad. My sister may or may not have known about him. But I know there are relatives she knows about that I don’t. Old family photo albums and Christmas card lists are other sources of clues.

Here’s how I cracked a tough problem. My great grandfather, Ralph Collins Farquhar, married a woman named Nellie McAdow. Nellie McAdow was a dead end. Her mother’s name was Mary Lillian Miller. I didn’t even have her father’s first name. All I found was a guy named McAdow, born in Ohio. A subsequent search revealed her father’s initials were A.G. and he was born in Pharisburg. So then I had A. G. McAdow, Pharisburg, May 25, 1859-January 15, 1904. I did a Google search and found the text of an old book that casually mentioned A. G. McAdow owned a store in Pharisburg in 1883. Great, so the guy’s in the history books, and I still can’t find his first name. Somehow, somehow, Mom knew his first name was Adalaska. Adalaska!? No wonder he went by “A. G.” I searched for Adalaska McAdow. Nothing at ancestry.com. But at Familysearch.com, I found 1880 census data. I found Adalaska living with someone he listed as his stepfather, Smith May, occupation farmer. His mother’s name was Virginia, and she was born in 1838 in Ohio, and they had a daughter, Lena, who was born in 1871. That was enough information to feed a couple more searches, which gave me Virginia’s maiden name, Evans, and the name of her first husband, James W. McAdow.

He was tougher than most, and I still don’t know nearly as much about this line as some others–including Nellie’s mother, Mary Lillian Miller’s line–but I broke the dead end.

I still have no clue why two people with normal names like James and Virginia would name their son Adalaska.

The grandmother who told my mom not to pry into the past remains a tough one. Social security records confirmed her dates of birth and death, and place of death, because my memory was hazy. Mom knows her parents were German immigrant Rudolph Keitsch and Irish immigrant Bessie Bonner. A Google search revealed Elizabeth Keitsch graduated from the Philadelphia College of Osteopathic Medicine in 1932. So far I’ve found absolutely no trace of her parents. I’m hoping that census records may help–a Google search for “ancestry records search” turns up several sites that will let you search various U.S. censuses for free, but they all use ancestry.com for something or another, which is down for maintenance as I write.

But I’m reasonably confident that once I can search census records, even my stubborn half-German grandmother will finally yield some information after all these years.

You can subscribe to ancestry.com to get to information that you can’t find online for free, and I’m sure that at some point I’ll end up doing that. For now I don’t have much reason to. You might as well see what you can find out for free as well. And I honestly hope you don’t have four grandparents like Elizabeth Keitsch. I hope yours are more like Ralph Collins Farquhar Jr., who took about 30 seconds to trace back to 1729, and whose grandmother, Elizabeth Stratton, led me back to the sixth century and gave me a splitting headache that forced me to temporarily abandon the search to return to this continent and four-digit years.

May all your lines do the same.

Royal roots

This past summer, someone told me he’d traced his genealogy back to William the Conqueror. I acted impressed, but I didn’t believe him. I dismissed it as wishful thinking.
When I traced myself back to the late 1600s, I felt pretty proud of myself. I mean, I wanted to go back further, but there just didn’t seem to be any trace of Adam Farquhar’s father or Dugal McQueen’s parents. Dugal was shipped over because he participated in a little rebellion intended to overthrow the King of England. I don’t know why Adam did. It was probably something boring, like an inability to get land.

The only way at the time to go back further was to trace a few other mothers’ families. The majority of them only went back a generation, maybe two. Then I got to my great great grandmother, Elizabeth Stratton. I mentioned that via her, I was a very distant cousin of the patriots John Adams and Samuel Adams. But it goes further than that. She also makes me a distant–very distant–cousin of Teddy Roosevelt, his wife, Franklin Roosevelt, Richard Nixon, Gerald Ford, and George Bush. I always knew I probably had distant relatives in Texas, but I didn’t expect Dubya to be among them.

But I wanted direct relatives, so I traced her back. And back. I started finding knights. Then I started finding people with higher noble titles, like Duke and Baron. Then I found someone with a title of Princess. One link later, I’d connected with William the Conqueror. And within a couple of hours, I’d also with Charlemagne (twice) and Alfred the Great.

I also found people who fought in the Battle of Hastings (besides William), a number of kings of France and Italy (you know something’s wrong when you cease to be impressed when you see a note on an ancestor that lists his occupation as the King of Italy), and people who appeared to be among the invaders who led to that whole Anglo-Saxon thing.

Eventually I had to return to the 19th century though. The inconsistency of last names gives you a headache when you research genealogy in 3-digit years.

Along the way, I found speculation that every person of European descent is probably related to Charlemagne. One genealogist has identified more than 50,000 descendants of Charlemagne. I’ve lived half my life in towns smaller than that. I wonder if the same thing is true of every person of British descent and William the Conqueror.

I think I also know where the plot of the John Goodman movie King Ralph came from now.

But now I want to trace my line back to 1382 in Scotland, when the Farquharson clan was founded. I now believe that Adam Farquhar’s father was a James Farquhar, who lived from 1670 to 1728 in Aberdeen, Scotland, and that James’ father was named Robert. That still leaves a gap of 300 years.

Finding my roots

A friend asked me a question. I still haven’t found the answer.
In search of the answer, I found, preserved in Google’s cache (I don’t know how much longer it would have been there) my father’s family tree, going all the way back to 1746 in, of all places, New Jersey. (The furthest back I’d ever been able to go was about 1840.) Supposedly my Farquhar ancestor who came over on the boat was one John Farquhar, who arrived in either North Carolina or Virginia sometime in the 1730s. But my source on that is about as reliable as the Weekly World News.

It appears that John Farquhar was actually the brother of my direct ancestor, a Scotsman who was named, appropriately (I think), Adam Farquhar. And John did eventually end up heading south. Adam headed west.

I never could trace Adam’s family back. There’s a huge gap between 1729, Adam’s birth date, and 1382, when Farquhar Shaw, the founder of Clan Farquharson, lived–“Farquhar” used to be a Gaelic first name, which can be translated “beloved man” or “honest man,” but Shaw was so highly regarded that his descendants called themselves “Farquharson,” literally, “Son of Farquhar.” Later, some of his descendants shortened the last name back to “Farquhar.” So how are Adam and Farquhar Shaw related? All that’s known is that Adam’s father was born between 1700 and 1710. We don’t even know his first name.

Anglos have always had problems with the name “Farquhar”–it’s pronounced FAR-kwur, in case you’re wondering–but we always hear goofy variations of the pronounciation, and far-out spellings. Adam apparently often went by “Adam Forker.” The children of his second wife tended to retain the Scottish spelling and pronounciation, while the children of his first wife tended to go by “Forker.”

Adam’s Farquhars mostly ended up in Ohio, and a lot of his Forkers ended up further west, in Kansas. One of his descendants, Della Forker, married a Kansan named Walter Percy Chrysler–the founder of Chrysler Corporation.

How many people can say their half fourth cousin twice removed married Walter Chrysler?

Probably more than you think. My great great great grandfather Dr. Edward Andrew Farquhar had 11 kids.

Dr. Edward connects me to a trio of other people you’re likely to have heard of–at least if you’re American. Dr. Edward married Elizabeth Stratton, whose great great great grandmother was named Deborah Adams. Deborah Adams’ father was named John Adams, and he was born in Plymouth, Mass., in 1630. That fact made me really start to wonder. You’ve probably heard of some people named Adams from Massachusetts.

Declaration of Independence signer Samuel Adams and U.S. presidents John Adams and John Quincy Adams were descended from an English immigrant named Henry Adams. Henry Adams’ grandfather, also named Henry Adams, had an older brother named Richard. Elizabeth Stratton is descended from Richard Adams, making her the sixth cousin three times removed of John and Samuel Adams. Which makes me the sixth cousin eight times removed of John and Samuel Adams.

This stuff is addictive.

Oh, and to answer the other obvious question: not counting the Adams family–which I’ve traced back to 1392 and expect to be able to go back at least one generation further–I can trace my earliest ancestor back to 1462, in England.

When will we take security seriously?

Overheard today at work:
“Hackers don’t usually work during the day, or on weekends…”

I guess by that same logic, I could say that I ran file servers with all ports exposed on the public Internet for years and never got hacked (just don’t mention that those years started in 1996 and ended in 1998).

It’s sad that there are people who still don’t take security seriously. The attitude I heard 10 years ago–“What? Do they want to look at the GIFs and JPEGs on my hard drive? If they can get in, they can have ’em!”–pervades today. Nobody’s interested in your GIFs and JPEGs because you don’t have anything that hasn’t been posted on Usenet’s alt.binaries groups a dozen times, but they want your high-speed connection. It doesn’t matter anymore how insignificant you are. If your computer is online, they want it.

I’m quickly reaching the point where I believe it’s socially irresponsible to have anything faster than a 56K dialup connection and not have a hardware-based firewall sitting between you and the Internet. I bought a couple of the low-end Network Everywhere-brand (made by Linksys) 4-port cable/DSL routers a year ago. I paid $50 apiece for them. That’s what you’ll pay for a shrink-wrapped “Internet Security” software package, but it’s more effective and it doesn’t slow your computer down. Even a one-computer household should have one.

As far as antivirus software goes, Grisoft offers antivirus software free for home use. Yes, it slows your computer down. If you don’t like that, run Linux. Grisoft’s AVG is free, effective, and easy to use. And it stamps outgoing e-mail, assuring your friends that your mail has been scanned. That’s comforting in these days.

Hopefully the typical computer user will soon outgrow the teenage it-can’t-happen-to-me mindset.

But I won’t hold my breath. Since hackers only work on weekdays, problems can only happen when I’m at work and my home PC is off, right?

Using your logs to help track down spammers and trolls

It seems like lately we’ve been talking more on this site about trolls and spam and other troublemakers than about anything else. I might as well document how I went about tracking down two recent incidents to see if they were related.
WordPress and b2 store the IP address the comment came from, as well as the comment and other information. The fastest way to get the IP address, assuming you haven’t already deleted the offensive comment(s), is to go straight to your SQL database.

mysql -p
[enter the root password] use b2database;
select * from b2comments where comment_post_id = 819;

Substitute the number of your post for 819, of course. The poster’s IP address is the sixth field.

If your blogging software records little other than the date and time of the message, you’ll have to rely on your Apache logs. On my server, the logs are at /var/log/apache, stored in files with names like access.log, access.log.1, and access.log.2.gz. They are archived weekly, with anything older than two weeks compressed using gzip.

All of b2’s comments are posted using a file called b2comments.post.php. So one command can turn up all the comments posted on my blog in the past week:

cat /var/log/apache/access.log | grep b2comments.post.php

You can narrow it down by piping it through grep a bit more. For instance, I knew the offending comment was posted on 10 November at 7:38 pm.

cat /var/log/apache/access.log | grep b2comments.post.php | grep 10/Nov/2003

Here’s one of my recent troublemakers:

24.26.166.154 – – [10/Nov/2003:19:38:28 -0600] “POST /b2comments.post.php HTTP/1.1” 302 5 “https://dfarq.homeip.net/index.php?p=819&c=1” “Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.5) Gecko/20031007 Firebird/0.7”

This line reveals quite a bit: Besides his IP address, it also tells his operating system and web browser.

Armed with his IP address, you can hunt around and see what else your troublemaker’s been up to.

cat /var/log/apache/access.log | grep 24.26.166.154
zcat /var/log/apache.access.log.2.gz | grep 24.26.166.154

The earliest entry you can find for a particular IP address will tell where the person came from. In one recent case, the person started off with an MSN search looking for information about an exotic airplane. In another, it was a Google search looking for the words “Microsoft Works low memory.”

You can infer a few things from where a user originally came from and the operating system and web browser the person is using. Someone running the most recent Mozilla Firebird on Linux and searching with Google is likely a more sophisticated computer user than someone running a common version of Windows and the version of IE that was supplied with it and searching with MSN.

You can find out other things about individual IP addresses, aside from the clues in your logs. Visit ARIN to find out who owns the IP address. Most ARIN records include contact information, if you need to file a complaint.

Visit Geobytes.com IP Locator to map the IP address to a geographic region. I used the IP locator to determine that the guy looking for the airplane was in Brooklyn, and the Microsoft guy was in Minneapolis.

Also according to my Apache logs, the guy in Brooklyn was running IE 6 on Windows XP. The guy in Minneapolis was running Mozilla Firebird 0.7 on Linux. (Ironic, considering he was looking for Microsoft information.) It won’t hold up in a court of law, but the geographic distance and differing usage habits give at least some indication it’s two different people.