Logo
Info Security
News
Advisories
 
WebKnight
Features
Download
Support
SQL Injection
Robots
Hot Linking
DoS
Blocklists
Googlebot Verifier
Testimonials
 
Log Analysis
Features
Download
Manual
 
Databases
User Agents
Http Headers
 
Members
Login
 

WHOIS

What is Whois?

Whois is a protocol used to find information about networks, domains and hosts. The whois records normally include data on the organizations and the contacts associated with these networks and domains.

Whois services operate through a whois server (standard TCP port 43). Anyone can connect to a whois server and send a query. The most common use of whois is finding information about domain names. For example, you can find information on a domain (eg: aqtronix.com) by querying the appropriate whois server. The second important use of whois is to lookup to who a certain ip address is assigned to.

Domain Whois

This is the most common use of whois. This can be used for checking available domain names before registering or to locate information on the domain name registrant.

The whois server for domain registration records are maintained by the organization authorized to register domain names. This depends on the specific domain name extension.

There are a number of registrars for the popular .com, .net and .org domains. This means that the actual domain records are generally not available from a single whois server.

Here is the procedure for looking up the popular top level domains:

1. Query whois.crsnic.net (or rs.internic.net) for .com & .net domains
   or whois.publicinterestregistry.net for .org domains.
2. Check the returned records to see if the domain is already registered.
   If it is, look for the authoritative whois server.
3. Query the authoritative whois server to obtain the actual whois records.

Domain whois: Whois servers for various domains
.com:rs.internic.com
.net:rs.internic.com
.org:whois.publicinterestregistry.net
.edu:rs.internic.com
.info:whois.afilias.info
.biz:whois.neulevel.biz
.aero:whois.information.aero
.coop:whois.nic.coop
.name:whois.nic.name
.uk:whois.nic.uk
.us:whois.nic.us
.ca:whois.cira.ca
.de:whois.nic.de
.ws:whois.nic.ws
.au:whois.aunic.net
.nu:whois.nic.nu
IP Whois

The Internet address space allocation is managed by a number of different organizations. These registries provide IP allocation information through their whois servers.

To find the allocation information for a specific IP address, query it first using the ARIN whois server. If the IP address is allocated through any of the other registries this information will be reported by ARIN. More lookups will be required to locate the actual data.

When large IP blocks are allocated to a large organization, there may be other whois servers internal to the organization. This means even more lookups.

IP Whois: Organizations responsible for IP allocations
  • American Region

    The Internet numbering resources for North America is managed by American Registry for Internet Numbers (ARIN).
    Web Site: www.arin.net
    Whois Server: whois.arin.net

  • Asia/Oceania Region

    Asia Pacific Network Information Centre (APNIC) serves the Asia Pacific region, comprising the countries in Asia and Australia.
    Web Site: www.apnic.net
    Whois Server: whois.apnic.net

  • Europe & Middle East

    The RIPE Network Coordination Centre (RIPE NCC) manages the IP allocation in Europe, The Middle East, The North of Africa and parts of Asia.
    Web Site: www.ripe.net
    Whois Server: whois.ripe.net

  • Latin American & Caribbean Region

    The Latin American and Caribbean IP address Regional Registry (LACNIC), is the emerging organization that will administer the Latin American and Caribbean Region IP address space.
    Web Site: www.lacnic.org
    Whois Server: whois.lacnic.net

  • African Region

    The African Network Information Center (AfriNIC), is the emerging organization that will administer IP allocation for Africa.
    Web Site: www.afrinic.org

Doing a lookup with telnet
  • Domain Lookup

    Open your command prompt and type:
    telnet whois.register.com 43
    Now type in any .com domain (e.g. aqtronix.com) and press enter (please note that the telnet window will not display the text that is being typed in).
    aqtronix.com
    Note: If you get too much information returned, try adding the word "domain" and a blank space before your domain name. This will reduce queries to domains only and leave out name servers.

  • IP Lookup

    Open your command prompt and type:
    telnet whois.ripe.net 43
    Now type an IP address in the European address space (e.g. 212.239.180.24).
    212.239.180.24



Published: 17/08/2003Document Type: General
Last modified: 24/08/2003Target: General
Visibility: PublicLanguage: English

[top] Print Edit


Comments (use this form to send comments to the author of the page):
Text:
How much is 4
4
+ 8 ?
E-mail: (optional)