WHOIS, the Registries and IP Allocation
Chapter Twenty-Eight
Syllabus topic Module 1, "DNS Enumeration and Domain Intelligence: ... WHOIS lookup, and ARIN databases to understand infrastructure mapping"
Pages 131 to 135 of 578
In one line
WHOIS answers "who registered this domain?" and the regional internet registries answer "who holds this block of addresses?". Together they turn a name or an address into an organisation and the range of addresses it controls.
In examination wording: WHOIS is a query protocol and the databases it serves, returning registration information for domain names and for IP address allocations; the five regional internet registries (ARIN, RIPE NCC, APNIC, LACNIC and AFRINIC) allocate address space within their regions and publish which organisation holds each range, enabling an assessor to determine the extent of an organisation's addressable estate.
Two different databases answering two different questions
Students conflate these constantly, so separate them at the start.
Domain WHOIS is about a name. It is served by registrars and registries in the domain-name system, and it answers: who registered company.test, through which registrar, when, until when, and which name servers did they set.
Registry WHOIS is about an address. It is served by the regional internet registries, and it answers: which organisation holds the block containing 203.0.113.45, how large is that block, and who is the technical contact.
Different systems, different operators, different data. The confusion matters because they are used at different points: domain WHOIS at the start, when you have a name; registry WHOIS in the middle, when you have an address and want to know how much else belongs to the same organisation.
Domain WHOIS: what a record holds
A domain WHOIS record has historically shown:
- the registrant, the person or organisation that owns the domain, with contact details;
- administrative and technical contacts, often different people;
- the registrar, the company through which it was registered;
- the dates: created, last updated, and expiry;
- the name servers, which ties back to the DNS chapters;
- the status codes, which record whether the domain is locked against transfer.
What it reveals to reconnaissance. An organisational registrant confirms ownership and often gives a role-based contact. Personal registrant details, where still exposed, give a named individual and their address and telephone number, which is a social-engineering target. The creation date indicates how long the organisation has existed under that name. The name servers confirm the DNS arrangement. And the status codes reveal whether the domain is protected against transfer, which tells an attacker whether a hijack attempt is worth considering.
The expiry date deserves its own paragraph, because it is the most actionable item on the record for a defender. A domain that lapses can be registered by anyone, who then controls the organisation's website addresses and, more damagingly, its mail: they can receive mail sent to the old domain, including password resets. Domains are lost this way regularly, usually secondary ones that nobody is watching because nobody uses them, and the recovery is difficult and sometimes impossible. Enable auto-renewal, keep the registrar account's payment details current, and monitor expiry for every domain the organisation owns, not just the important ones.
WHOIS, the Registries and IP Allocation
Privacy: why modern WHOIS shows less
A student working from older material will expect names and addresses and mostly will not find them. Two changes account for it.
Registrar privacy services. For a small fee, or free by default with many registrars, the registrant's details are replaced in the public record by the privacy service's own, which forwards correspondence. The real registrant is still known to the registrar, but not to the public.
Data-protection law. The European General Data Protection Regulation caused registries and registrars to redact personal data from public WHOIS output as a matter of course, because publishing an individual's name, address, email and telephone worldwide is difficult to justify. The effect extends well beyond Europe because the operators applied it broadly.
So the modern position is: organisational domains often still show a company name and a role-based contact; domains held by individuals usually show a privacy service or redacted fields. For a defender this means an exposed personal name and address in a WHOIS record is a finding, not the expected state, and the remedy is to enable the registrar's privacy service.
A caution for accuracy: historical WHOIS data persists. Services archive past records, so details redacted today may remain visible in a record from before privacy was applied. Enabling privacy protects the future, not the past.
The regional internet registries
Addresses are allocated in a hierarchy. At the top is the global coordinating body, which allocates large blocks to five regional internet registries, each covering a part of the world. Those allocate to internet providers and to large organisations, who assign to customers.
| Registry | Region |
|---|---|
| ARIN | United States, Canada, parts of the Caribbean |
| RIPE NCC | Europe, the Middle East, Central Asia |
| APNIC | Asia and the Pacific, including India |
| LACNIC | Latin America and the Caribbean |
| AFRINIC | Africa |
MU's syllabus names ARIN because it is the best known and its database is the model; an Indian organisation's addresses are normally registered with APNIC, and the query is identical in form.
What a registry lookup returns. Given one address, it returns the block that contains it, the organisation that holds the block, the block's size, and technical and abuse contacts. Larger organisations also register autonomous system numbers, which identify their networks in internet routing, and from an autonomous system number all the address ranges it announces can be listed.
WHOIS, the Registries and IP Allocation
Why the address range is the most useful thing in this chapter
Because it defines boundaries, and boundaries are what both an attacker and an assessor need.
For an attacker, knowing that an organisation holds a range means every address in it is worth examining, including hosts with no DNS name at all. One discovered web server expands into a block of addresses to sweep.
For an assessor, the same lookup answers the question the authorisation chapter raised: what actually belongs to the client? If the address is inside a range registered to the client, it is theirs and the client can authorise testing of it. If it is inside a hosting or cloud provider's range, it is not, and the client cannot grant permission over the provider's infrastructure; the provider's own testing policy applies, and some require notification.
That distinction prevents the commonest scoping error in the profession, and it is why registry lookups belong in the pre-engagement work rather than in the middle of a test.
For a defender, the same lookup is an inventory check: sweeping your own registered ranges finds hosts you have forgotten, which is the point the enumeration chapter made from the other direction.
A worked example
Nisha maps her organisation's estate, beginning with a name and finishing with a boundary.
- Domain WHOIS on
company.testshows an organisational registrant, a role-based contact, a creation date of 2011, expiry in fourteen months with the status indicating a registrar lock is in place, and two name servers. Sound, except that a second domain the company owns,company-india.test, shows a former employee's personal name and mobile number and expires in six weeks with no lock. - She resolves the main site to an address and queries APNIC, which returns a range held by a hosting provider. So the website is hosted, and the provider's infrastructure is not the client's to authorise.
- She resolves the VPN endpoint, queries APNIC again, and this time the range is registered to the company itself, a block of addresses along with an autonomous system number. That range is the client's own estate.
- Sweeping the company's own range for names and responses finds three hosts that appear in no DNS record and on no inventory.
Her findings: the second domain's personal registrant data and imminent expiry without a lock (urgent, and a hijack and impersonation risk); the confirmed boundary between client-owned addresses and provider-owned ones, which is recorded in the scope; and three unregistered hosts inside the company's own range.
The middle finding is the one that makes the engagement safe, and it is invisible unless somebody does this lookup.
What beginners get wrong
- Conflating domain WHOIS with registry WHOIS. One is about a registered name and comes from registrars; the other is about an address block and comes from a regional registry.
- Expecting personal details. Privacy services and data-protection redaction are now normal. An exposed personal record is a finding, not the default.
- Assuming privacy fixes the past. Historical WHOIS archives retain what was published before privacy was enabled.
- Thinking ARIN covers the world. There are five regional registries; India's is APNIC.
- Ignoring expiry and lock status. A lapsed domain can be taken over and used to receive the organisation's mail, including password resets. Auto-renewal, monitoring and registrar lock are the controls.
- Assuming everything resolving to a client's name is in scope. If the address belongs to a hosting provider, the client cannot authorise testing of that infrastructure.
WHOIS, the Registries and IP Allocation
Quick revision
- Domain WHOIS: registrant, contacts, registrar, created/updated/expiry, name servers, status codes (transfer lock). Served by registrars and registries.
- Registry WHOIS: which organisation holds an address block, the block's size and abuse contacts, and autonomous system numbers. Served by the five regional registries: ARIN (North America), RIPE NCC (Europe, Middle East), APNIC (Asia-Pacific, India), LACNIC (Latin America), AFRINIC (Africa).
- Modern domain records are usually privacy-protected or redacted; an exposed personal registrant is a finding. Historical archives persist.
- Expiry and registrar lock are the actionable defensive items: a lapsed domain can be hijacked and used to receive the organisation's mail.
- The address range is the most useful output: it expands one host into an estate for enumeration, and it settles what the client owns and can lawfully authorise.
Test yourself
- Distinguish domain WHOIS from a regional registry lookup.
Domain WHOIS returns registration details for a name (registrant, registrar, dates, name servers, status) and is served by registrars and domain registries. A regional registry lookup returns which organisation holds the address block containing a given IP address, the block's extent and its contacts, and is served by one of the five regional internet registries.
- Why has WHOIS output become less revealing, and what does that mean for an assessor?
Registrar privacy services replace registrant details with a proxy, and data-protection law, principally the GDPR, caused widespread redaction of personal data. For an assessor it means exposed personal details in a record are a finding to report rather than the expected result, and that historical archives may still show pre-redaction data.
- Which registry serves India, and why does the syllabus mention ARIN?
APNIC serves the Asia-Pacific region including India. The syllabus names ARIN because it is the best-known regional registry and its database is the model for the others; the query technique is identical.
- Why is an address-range lookup important before testing begins?
Because it determines what the client actually owns. Addresses inside a range registered to the client are the client's own estate and can be authorised; addresses inside a hosting or cloud provider's range belong to that provider, which the client cannot authorise, so the provider's testing policy applies instead.
WHOIS, the Registries and IP Allocation
- What are the risks of an unmonitored domain expiry, and what controls address them?
An expired domain can be registered by anyone, who can then serve content from the organisation's addresses and receive mail sent to the domain, including password-reset messages, enabling impersonation and account takeover. The controls are auto-renewal, current payment details on the registrar account, expiry monitoring for every domain owned, and registrar lock against unauthorised transfer.
The rest of this subject
These notes are cut from the University's printed syllabus. Open the syllabus itself for the same subject.