A third party security audit is the IT equivalent of a colonoscopy. It's long, intrusive, very uncomfortable, and when it's done, you'll have seen things you really didn't want to see, and you'll never forget that you've had one.
About the only real way to "catch" him would be to go to into EVERY router he has accessed wireless-ly and see if his cards MAC address is in the log files. But then again, if he was smart when he did this, then he cloned or faked his MAC address with macchanger or another MAC changing soft. The IPs in the router logs probably won't matter, all they'll show is an local IP somewhere within in the range of the gateway the guy was on.
In a word, unless he changed his MAC addy,...theres not much you can have to go on to "prove" it was him. And its not illegal to ban evade..lol. I'm sure we have many here on our forums who have ban evaded successfully. Its just a pain in the ass to you to have to deal with this guy. Eventually, he'll bore with this little game and move on...and probably only "occasionally" jack with you.
[CENTER][FONT=Book Antiqua][SIZE=5][B][COLOR=blue][FONT=Courier New][COLOR=red]--=[/COLOR][/FONT]Xploitz[FONT=Courier New][COLOR=red]=--[/COLOR][/FONT][/COLOR][/B][/SIZE][/FONT][FONT=Courier New][COLOR=Black][SIZE=6][B] ®[/B][/SIZE][/COLOR][/FONT][/CENTER]
[CENTER][SIZE=4][B]Remote-Exploit.orgs Master Tutorialist.[/B][/SIZE][SIZE=6][B]™
[/B][/SIZE]
[URL="http://forums.remote-exploit.org/showthread.php?t=9063"][B]VIDEO: Volume #1 "E-Z No Client WEP Cracking Tutorial"[/B]
[/URL]
[URL="http://forums.remote-exploit.org/showthread.php?t=7872"][B]VIDEO: Volume #2 "E-Z No Client Korek Chopchop Attack Tutorial"[/B]
[/URL]
[URL="http://forums.remote-exploit.org/showthread.php?t=8230"][B]VIDEO: Volume #3 "E-Z WPA/WPA2 Cracking Tutorial"[/B][/URL]
[URL="http://forums.remote-exploit.org/showthread.php?t=8041"][B]VIDEO: Volume #4 "E-Z Cracking WPA/WPA2 With Airolib-ng Databases"[/B][/URL]
[/CENTER]
[CENTER][FONT=Book Antiqua][SIZE=5][B][COLOR=blue][FONT=Courier New][COLOR=red]--=[/COLOR][/FONT]Xploitz[FONT=Courier New][COLOR=red]=--[/COLOR][/FONT][/COLOR][/B][/SIZE][/FONT][FONT=Courier New][COLOR=Black][SIZE=6][B] ®[/B][/SIZE][/COLOR][/FONT][/CENTER]
[CENTER][SIZE=4][B]Remote-Exploit.orgs Master Tutorialist.[/B][/SIZE][SIZE=6][B]™
[/B][/SIZE]
[URL="http://forums.remote-exploit.org/showthread.php?t=9063"][B]VIDEO: Volume #1 "E-Z No Client WEP Cracking Tutorial"[/B]
[/URL]
[URL="http://forums.remote-exploit.org/showthread.php?t=7872"][B]VIDEO: Volume #2 "E-Z No Client Korek Chopchop Attack Tutorial"[/B]
[/URL]
[URL="http://forums.remote-exploit.org/showthread.php?t=8230"][B]VIDEO: Volume #3 "E-Z WPA/WPA2 Cracking Tutorial"[/B][/URL]
[URL="http://forums.remote-exploit.org/showthread.php?t=8041"][B]VIDEO: Volume #4 "E-Z Cracking WPA/WPA2 With Airolib-ng Databases"[/B][/URL]
[/CENTER]
I hear ya brother. You, me and a whole lot of other people as well. I'm just glad to see you're still around. We've missed ya.
If there's anything at all I can do to help, please please please don't hesitate to let me know. I'm working on some pretty big things right now and if you have any spare time, trust me I know it's hard to find any nowadays, shoot me a message and I'll fill you in.
"The goal of every man should be to continue living even after he can no longer draw breath."
~ShadowKill
[CENTER][FONT=Book Antiqua][SIZE=5][B][COLOR=blue][FONT=Courier New][COLOR=red]--=[/COLOR][/FONT]Xploitz[FONT=Courier New][COLOR=red]=--[/COLOR][/FONT][/COLOR][/B][/SIZE][/FONT][FONT=Courier New][COLOR=Black][SIZE=6][B] ®[/B][/SIZE][/COLOR][/FONT][/CENTER]
[CENTER][SIZE=4][B]Remote-Exploit.orgs Master Tutorialist.[/B][/SIZE][SIZE=6][B]™
[/B][/SIZE]
[URL="http://forums.remote-exploit.org/showthread.php?t=9063"][B]VIDEO: Volume #1 "E-Z No Client WEP Cracking Tutorial"[/B]
[/URL]
[URL="http://forums.remote-exploit.org/showthread.php?t=7872"][B]VIDEO: Volume #2 "E-Z No Client Korek Chopchop Attack Tutorial"[/B]
[/URL]
[URL="http://forums.remote-exploit.org/showthread.php?t=8230"][B]VIDEO: Volume #3 "E-Z WPA/WPA2 Cracking Tutorial"[/B][/URL]
[URL="http://forums.remote-exploit.org/showthread.php?t=8041"][B]VIDEO: Volume #4 "E-Z Cracking WPA/WPA2 With Airolib-ng Databases"[/B][/URL]
[/CENTER]
Maybe I will.
To be honest, I'd just like to know who he is and I'm betting 90% it's some script kiddie or a hacker wannabe. There is no assurance that the flash trick is going to work, but it's worth a try IMO. Maybe there's an alternate way to do it with javascript to bypass a client-side anonymizer tho most of these methods can be easily rendered useless by installing a plugin such as NoScript on your Firefox.
Also, I'm adding the anonymizer IP's to the banlist.
EDIT: Is there a good and recent IP banist for the popular proxies and anonymizers?
I have the card in me head, but you have the memory problems?
Does he simply spam? Or does he actually respond to posts? If he has a grudge against you and you can get him to talk you could most likely social engineer a good bit of information out of him. Remember to use metadata, and mask your intentions ie.
Get him to brag about his hardware, chances are he is going to want to show you how big his "epeen" is, and reveal what kind of box he is using.
Get him to post a picture on an image hosting site or something and compare the ip address, he may slip up when not specifically trying to spam you.
Compare syntax, if you have a feeling that you know this person in a Jekyl/Hyde kinda way you may have all the proof you need. People tend to use similer sets of phrases or punctuate in ways that are discernible from others. Or use slang or colloquialisms specific to certain regions.
(My personal favorite) Create an account and help him spam your board a few times. Do something really "cool" like defacing the site that will impress him (easy since you are a mod) tell him that the mod pissed you off just like him and basically become his buddy long enough to give himself away. If you can get his icq/aim/email its game over, especially if you get him to do a direct connect file transfer.
I know its cliche, but sometimes you need to think outside the box, its amazing what you can talk people into revealing about themselves if you can do a little play-acting. I always have worked on the basis that no system is uncrackable and no person untraceable it all just depends on how much effort you are willing to put into it.
As for what you can do when you find him, once you have an ip its only a skip away from a phone number. Call the bastard up and tell him his own name, address, next of kin, social security number, then hang up. If he is using an anonymiser he will probably be scared ****less. Or if he is 12 and living with his parents (as i suspect) just tell his mommy that the next phone call you make is to the feds, see how quick he gets his puter taken away.
Morpheus: "You take the blue pill - the story ends, you wake up in your bed and believe whatever you want to believe. You take the red pill - you stay in Wonderland and I show you how deep the rabbit-hole goes."
Neo: "What if I take both?"
Morpheus: "Don't do that! You end up like Nick Nolte!"