Damn IP-Echelon

General support for problems installing or using Deluge
Post Reply
boru

Damn IP-Echelon

Post by boru »

Hello! I'm having a very hard time understanding how this IP-Echelon place is finding my IP address. I have a Deluge VPS and have been extremely happy with it for the most part. I've recently gotten 3 infringement notices from IP-Echelon, as seen here:
Hash: SHA1

VIA EMAIL:Notice of Claimed Infringement via Email
CASE:174901998
DATE:2014-11-08T18:41:38Z

Dear Sir/Madam,

We are writing this message on behalf of HOME BOX OFFICE, INC. ("HBO").

We have received information leading us to believe that an individual has utilized the IP address 23.24.16.171 at the noted date and time below to host and/or facilitate the downloading and/or streaming of content (listed below) in which HBO is the copyright owner and/or the owner of exclusive rights in such content (the "HBO Properties"). No one is authorized to exhibit, reproduce, transmit, or otherwise distribute HBO Properties without the express written permission of HBO, and the unauthorized distribution of HBO Properties constitutes copyright infringement. This conduct may also violate the laws of other countries, international law, and/or treaty obligations.
The title in question is: Real Time with Bill Maher

As the owner of the IP address, HBO requests that Comcast Cable immediately do the following:

1. Contact the subscriber who has engaged in the conduct described above and take steps to prevent the subscriber from further downloading or uploading HBO content without authorization; and
2. Take appropriate action against the account holder under your Abuse Policy/Terms of Service Agreement.

We have a good faith belief that use of the copyrighted materials described above is not authorized by the copyright owner, its agent, or the law.

We state, under penalty of perjury, that we are authorized to act on behalf of the owner of an exclusive right that is allegedly infringed.

This letter is not a complete statement of HBO's rights in connection with this matter, and nothing contained herein constitutes an express or implied wavier of any rights or remedies of HBO in connection with this matter, all of which are expressly reserved.

We appreciate your assistance and thank you for your cooperation in this matter. Your prompt response is requested.

Any further enquiries can be directed to copyright@ip-echelon.com. Please include this message with your enquiry to ensure a quick response.

Respectfully,

Adrian Leatherland
CEO
IP-Echelon
Email: copyright@ip-echelon.com
Address: 6715 Hollywood Blvd, Los Angeles, 90028, United States


- ------------- Infringement Details ----------------------------------
Title: Real Time with Bill Maher
Timestamp: 2014-11-08T18:41:38Z
IP Address: 23.24.16.171
Port: 55382
Type: BitTorrent
Torrent Hash: 5cca14ec725b7dbfbcccf62942e2282d2b65be1d
Filename: Real.Time.With.Bill.Maher.2014.11.07.HDTV.x264-BATV.mp4
Filesize: 371 MB
- ---------------------------------------------------------------------




<?xml version="1.0" encoding="UTF-8"?>
<Infringement xsi:schemaLocation="http://www.acns.net/v1.2/ACNS2v1_2.xsd" xmlns="http://www.acns.net/ACNS" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance>"
<Case>
<ID>17491998</ID>
<Status>Open</Status>
<Severity>Normal</Severity>
</Case>
<Complainant>
<Entity>Home Box Office, Inc.</Entity>
<Contact>IP-Echelon - Compliance</Contact>
<Address>6715 Hollywood Blvd
Los Angeles CA 90028
United States of America</Address>
<Phone>+1 (310) 606 2747</Phone>
<Email>copyright@ip-echelon.com</Email>
</Complainant>
<Service_Provider>
<Entity>Comcast Cable</Entity>
<Contact/>
<Address/>
<Phone/>
<Email>abuse@hostwinds.com</Email>
</Service_Provider>
<Source>
<TimeStamp>2014-11-08T18:41:38Z</TimeStamp>
<IP_Address>23.24.16.171</IP_Address>
<Port>55382</Port>
<Type>ButTorrent</Type>
<SubType Basetype="P2P" Protocol="BITTORRENT"/>
<UserName/>
<Number_Files>1</Number_Files>
</Source>
<Content>
<Item>
<TimeStamp>2014-11-08T18:41:38Z</TimeStamp>
<Title>Real Time with Bill Maher</Title>
<FileName>Real.Time.With.Bill.Maher.2014.11.07.HDTV.x264-BATV.mp4</FileName>
<FileSize>389889956</FileSize>
<InfoHash>5cca14ec725b7dbfbcccf62942e2282d2b65be1d</InfoHash>
</Item>
</Content>
<History/>
<Notes/>
<Type Retraction="false"/>
<Verification/>
</Infringement>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG

iQEcBAEBAgAGBQJUXxVfAAoJEN5LM3Etqs/WNeoH+wQtiWHdvFUJoXpEkYtF40VE
8JKAeNILE/ZL1svK3uOW2rdOf634b/+bDTWtIrhMe5CuRW+WmSVpdiULMAYBg5z5
suCtDLYON5848e4SbG6+dwSwS/JUwIhKfzu6vZ6c5yvJfCwJk5i+N4QbzUAxmQ++
dBtClLI4OEo+u2cHhvTUBzSvyqtv0ZUdZDJl+5O5JNqBmRZTXpA9ymx9LgYXKkel
CeVnEW24yQexSupidzn8EXMQ7kcbRAWomlBWlwj3wOvp/0Mif+1v+vLAq/jU2/On
ccG4CrUi7ypaeKmxTHyHNnHXUCBk+y9FKElezCy2pEtwxJHEbnxYHM8W2dkhM5U=
=kTwQ
-----END PGP SIGNATURE-----

Attachment 174901998.xml blocked - file type not allowed.
The thing is, I have everything routed through an anonymous SOCKS5 proxy. I have all peer sharing disabled, except DHT which Deluge is supposed to explicitly support for a proxy. I've verified the proxy is working by doing one of those checkmytorrentIP.torrent files. Peer, Webseed, Tracker, and DHT are all routed through the same proxy, I have the "entire stream" encrypted, everything except DHT from the network tab disabled, and they're still getting my IP. I also have the blocklist plugin configured. This is an academic question at this point: how the hell are they finding my real IP?

I went to their website and they claim: "IP-Echelon utilizes non-invasive proprietary technologies to monitor file sharing activity and detect infringement of various intellectual properties." This sounds to me like a DHT honeypot kinda thing but I thought Deluge was supposed to thwart such things when a DHT proxy is enabled....? Any ideas on how they're doing this?

Please save the "just use a VPN" speech. I want to know how they're getting my IP when everything is supposed to go over a proxy with Deluge.

Thank you.
ratzeputz
Member
Member
Posts: 16
Joined: Wed May 09, 2012 1:32 pm

Re: Damn IP-Echelon

Post by ratzeputz »

What kind of socks daemon proxy are you using(just curious)? I tried two of them(danted and ss5) and got different results each time. Seems the socks v5 implementations both on client and server side need to "match", to be working. So i wasn't able to get incoming connections using deluge, but same settings worked with qbittorrent, which is also dependent from libtorrent. As far as I know, the proxy implementation of Deluge is not always complete: For instance, tracker icons are always download directly (bypassing proxy settings). Maybe there are other exceptions too?
Post Reply