1. Introduction
When an individual or business entity registers a domain name with a lot of information to register, the settings for registering privacy are various, and we can collect this information and use it to verify the IP space. Based on this clue, you can find information about other websites that belong to that person or business entity, even the number and address of the core employee.
The following table is a list of top registries:
Institutions |
Domain name |
AFRINIC |
Http://www.afrinic.net |
APNIC |
Http://www.apnic.net |
ARIN |
Http://www.arin.net |
Iana |
Http://www.iana.net |
Icann |
Http://www.icann.net |
Lacnic |
Http://www.lacnic.net |
NRO |
Http://www.nro.net |
RIPE |
Http://www.ripe.net |
InterNic |
Http://internic.net |
2. Using WHOIS to gather information 2.1 basic usage
The basic usage of whois is as follows: Admiralmarkets.com as an example (for test use only, no other use).
# whois admiralmarkets.com
The results are as follows:
Domain name: domainname.
Registrar: Registered person registering a domain name
Whois Server: whois.godaddy.com
At the bottom is the update date, creation date and expiration time of the domain name registration.
The following is more detailed information about the registrant or business, including name, city name, Street, week line, phone number, email, etc.
2.2 Specify which registration authority to use
Many times, we need to designate specific registries for queries, and WHOIS is implemented with the-H option. "54.72.241.30" is the IP address of the admiralmarkets.com domain name, which can be obtained by pinging.
# whois -h whois.apnic.net 54.72.241.30
2.3 Querying IP Location
Whois can also be used to query the country where the IP address belongs
# whois -h whois.apnic.net 54.72.241.30 | grep Country
This result can be found in 2.2 of the results. Of course, you can also use the grep option to see what you're interested in.
3. Defense methods
Registering a domain name is a privacy option that restricts the disclosure of the registration information, which is replaced by the information provided by the private agent. In this case, if someone wants to contact the registrant, the private agent is contacted first, and then the registrant is notified about the issue by the agent.
Penetration testing IP and domain name information collection verification