2.2.7 WHOIS Footprinting

WHOIS Lookup

  • WHOIS databases are maintained by Regional Internet Registries and contain the personal information of domain owners.
  • WHOIS query returns:
    • Domain name details
    • Contact details of domain owner
    • Domain name servers
    • NetRange
    • When a domain has been created
    • Expiry records
    • Records last updated
  • Information obtained from WHOIS database assists an attacker to:
    • Gather personal information that assists to perform social engineering
  • Regional Internet Registries (RIRs):
    • AFRINIC (African Network Information Center)
    • ARIN (American Registry for Internet Numbers)
    • APNIC (Asia Pacific Network Information Center)
    • RIPE (Reseaux IP Europeens Network Coordination Centre)
    • LACNIC (Latin American and Caribbean Network Information Center)

