Skip to contentExploitQuest

Lesson 1 of 1 in whois

The Filing Cabinet, Not the Machine

Everything whois tells you is what somebody typed on a form. That is its weakness and, occasionally, its whole value.

3 min read

Not yet reviewed

nmap, dig and ffuf all ask a machine a question and report what it says. whois is different in kind: it asks a registry, and the registry has never spoken to the server. Everything it returns is what somebody typed when they registered the name, plus whatever a registrar has been told since.

Note

Hold that distinction the whole way through this module. A whois record that disagrees with reality is not a broken record — it is a record, doing exactly what a record does, which is remembering the day it was written.

What is actually in there

Your turn

Look up brightpath.example. Find out which registrar holds it and when it was first registered.

you@practice
Practice shell — nothing here is real. Type 'help' to begin.

The disagreement is the finding

What the registry says

Name Server:  ns1.oldhost.example
Name Server:  ns2.oldhost.example

What the machine says

The site resolves and is served somewhere else entirely.

Somebody migrated hosting and never updated the registration. That tells you there was a migration, roughly when, and that whoever ran the old provider account may still exist — which is a thread, and threads are what reconnaissance produces.

What the dates are for

Creation Date      how long this organisation has had this name
Updated Date       when the record last changed - often a migration
Registry Expiry    when somebody has to remember to renew it
  1. Line 1A domain registered last week and a domain registered in 2004 are very different propositions, and it is the fastest way to tell a business from something that appeared to look like one.
  2. Line 3The one that has ended companies. An expired domain can be registered by anybody, and it takes their email, their password resets and their published identity with it.

Take care

Redaction has changed what this tool is for. It used to name a person and frequently an address; now it usually names an organisation or nothing. Anybody teaching whois as a way to find a human being is describing an internet that mostly stopped existing — and if a record *does* still carry a person's details, treat that as somebody's mistake rather than as an invitation.

There is nothing to detect

This is the only module in this course with no defensive beat, and the absence is the point: a whois query goes to a registry, so the target learns nothing. There is no log entry, no alert to tune and no threshold to set.

The defensive work is entirely in what you publish. Check what your own records say, keep the registrant redacted, put an abuse address on it that somebody reads, and put the expiry date in a calendar owned by more than one person.

A whois record lists nameservers that do not match where the site is actually served. What is the most useful reading?