daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

43-pentesting-whois.md (8664B)


      1 ---
      2 title: "43 - Pentesting WHOIS"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/43-pentesting-whois.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/43-pentesting-whois.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 43 - Pentesting WHOIS
     14 
     15 ## Basic Information
     16 
     17 The **WHOIS** protocol provides text-based queries for information about Internet resources, including domain names, IP address blocks, and autonomous systems. The data model and query syntax are service-specific; RFC 3912 standardizes only the simple transport exchange.<sup>[[3]](#references)</sup>
     18 
     19 **Default port:** 43
     20 
     21 ```text
     22 PORT   STATE  SERVICE
     23 43/tcp open   whois?
     24 ```
     25 
     26 From an offensive point of view, remember that **WHOIS is a plain-text TCP service**: the client sends a query terminated by CRLF, the server returns text, and the **connection close marks the end of the response**. The protocol has no built-in authentication, integrity, or confidentiality.<sup>[[3]](#references)</sup>
     27 
     28 ### Modern Reality: WHOIS vs RDAP
     29 
     30 For Internet domain registration data, **WHOIS is no longer the authoritative option for many public gTLD workflows**. ICANN sunset WHOIS for gTLD registration data on **2025-01-28**, making **RDAP** the protocol to prefer for machine-readable domain registration lookups.<sup>[[1]](#references)</sup>
     31 
     32 However, TCP/`43` is still worth testing because it keeps appearing in:
     33 
     34 - **Legacy or private WHOIS services**
     35 - **RIR / IP allocation workflows**
     36 - **Internal registries and custom asset databases**
     37 - **Third-party web tools and old automation** that still trust WHOIS responses
     38 
     39 If your goal is **reverse whois**, broader asset expansion, or recursive external recon, check [the External Recon Methodology page](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/external-recon-methodology/README.md) to avoid duplicating work here.
     40 
     41 ## Enumerate
     42 
     43 Get all the information that a whois service has about a domain:
     44 
     45 ```bash
     46 whois -h <HOST> -p <PORT> "domain.tld"
     47 printf 'domain.tld\r\n' | nc -vn <HOST> <PORT>
     48 ```
     49 
     50 If you find a public-facing WHOIS service, test both **domain** and **IP/ASN** style queries because many implementations expose different backends or parsers depending on the object type:
     51 
     52 ```bash
     53 # Domain
     54 printf 'example.com\r\n' | nc -vn <HOST> 43
     55 
     56 # IP / CIDR / ASN examples
     57 printf '8.8.8.8\r\n' | nc -vn <HOST> 43
     58 printf 'AS15169\r\n' | nc -vn <HOST> 43
     59 ```
     60 
     61 Sometimes a WHOIS response identifies the database or upstream registry being queried:
     62 
     63 ![Domain - IP / CIDR / ASN examples: Notice than sometimes when requesting for some information to a WHOIS service the database being used appears in the response](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28301%29.png)
     64 
     65 ### Referral Chasing and Better Enumeration
     66 
     67 Useful WHOIS enumeration is often hidden behind **referrals**. One server may only identify the next authoritative service for a TLD or RIR. Test referral handling manually because custom clients and gateways can redact fields inconsistently or expose backend metadata.<sup>[[4]](#references)</sup>
     68 
     69 Useful options and helpers:
     70 
     71 ```bash
     72 # Ask IANA first and then follow the authoritative referral (common Linux whois clients)
     73 whois -I example.com
     74 whois -I 8.8.8.8
     75 
     76 # Let Nmap follow domain/IP WHOIS referrals automatically
     77 nmap --script whois-domain <target>
     78 nmap --script whois-ip <target>
     79 
     80 # For IP ranges, disable the WHOIS cache if you care about smaller delegated blocks
     81 nmap --script whois-ip --script-args whois.whodb=nocache <target>
     82 ```
     83 
     84 Interesting fields to pivot on when the service is not fully redacted:
     85 
     86 - **Registrar / Org / abuse contact** for phishing reporting or org-mapping
     87 - **Creation / update / expiration times** to spot newly registered infrastructure
     88 - **Nameservers** to cluster domains managed by the same operator
     89 - **Referral server names** to find legacy or forgotten WHOIS infrastructure
     90 
     91 ### RDAP as the Structured Successor
     92 
     93 Even if the exposed service is classic WHOIS on port `43`, check whether the same provider also offers **RDAP** because RDAP is often easier to parse and better for automation:
     94 
     95 ```bash
     96 curl -s https://www.rdap.net/domain/example.com | jq
     97 curl -s https://rdap.arin.net/registry/ip/8.8.8.8 | jq
     98 ```
     99 
    100 A 2024 measurement study comparing WHOIS and RDAP at scale found that they are **not always interchangeable**, with inconsistencies in fields such as registrar identifiers, creation dates, and nameservers. If a recon pipeline depends on those values, compare both sources before making decisions.<sup>[[5]](#references)</sup>
    101 
    102 ## Offensive Notes
    103 
    104 ### Backend Injection in Custom WHOIS Gateways
    105 
    106 Custom WHOIS gateways commonly query a registry database or proxy another directory. If input is concatenated into a backend query, **SQL injection** or another injection class may be possible. For example, an authorized lab test might send `whois -h 10.10.10.155 -p 43 "a') or 1=1#"`; this is an implementation flaw, not a property of the WHOIS protocol.
    107 
    108 Do not limit testing to SQLi. In internal or niche WHOIS deployments, the query can be proxied to:
    109 
    110 - SQL / NoSQL backends
    111 - LDAP directories
    112 - shell wrappers around other lookup tools
    113 - HTTP APIs used by registrar or asset-management portals
    114 
    115 So fuzz with payloads for **SQLi**, **LDAP injection**, delimiter abuse, very long strings, and malformed UTF-8 / control characters. The protocol itself is simple; the dangerous part is usually the **parser or backend glue code**.
    116 
    117 ### Rogue / Stale WHOIS Servers
    118 
    119 A relevant 2024-2025 attack path is abusing **outdated WHOIS trust**. If a registry or tool changes its WHOIS hostname and the old domain expires, an attacker may be able to register the old hostname and operate a **rogue WHOIS server**.<sup>[[2]](#references)</sup>
    120 
    121 That gives the attacker control over the response body seen by:
    122 
    123 - old WHOIS clients with hardcoded server mappings
    124 - web applications that fetch WHOIS output and render it back to users
    125 - automation that still uses WHOIS for domain validation or ownership workflows
    126 
    127 This matters because a rogue WHOIS response can become an entry point for:
    128 
    129 - **stored/reflected XSS** in web WHOIS frontends
    130 - **parser bugs / command injection / eval bugs** in libraries consuming the text response
    131 - **bad automation decisions** when systems trust attacker-controlled WHOIS contact data
    132 
    133 When you find a private or legacy WHOIS service, always check whether the returned `refer:` / `Whois Server:` values, banners, or TLD mappings point to **expired or attacker-registerable domains**.
    134 
    135 ## Shodan
    136 
    137 - `port:43 whois`
    138 
    139 ## HackTricks Automatic Commands
    140 
    141 ```yaml
    142 Protocol_Name: WHOIS    #Protocol Abbreviation if there is one.
    143 Port_Number:  43     #Comma separated if there is more than one.
    144 Protocol_Description: WHOIS         #Protocol Abbreviation Spelled out
    145 
    146 Entry_1:
    147   Name: Notes
    148   Description: Notes for WHOIS
    149   Note: |
    150     The WHOIS protocol serves as a standard method for inquiring about the registrants or holders of various Internet resources through specific databases. These resources encompass domain names, blocks of IP addresses, and autonomous systems, among others. Beyond these, the protocol finds application in accessing a broader spectrum of information.
    151 
    152 
    153     https://book.hacktricks.wiki/en/network-services-pentesting/43-pentesting-whois.html
    154 
    155 Entry_2:
    156   Name: Banner Grab
    157   Description: Grab WHOIS Banner
    158   Command: whois -h {IP} -p 43 {Domain_Name} && printf '{Domain_Name}\r\n' | nc -vn {IP} 43
    159 
    160 Entry_3:
    161   Name: Nmap WHOIS Referrals
    162   Description: Follow WHOIS referrals for domain and IP lookups
    163   Command: nmap --script whois-domain,whois-ip --script-args whois.whodb=nocache {IP}
    164 ```
    165 
    166 ## References
    167 
    168 - [1] [ICANN Update: Launching RDAP; Sunsetting WHOIS](https://www.icann.org/en/announcements/details/icann-update-launching-rdap-sunsetting-whois-27-01-2025-en)
    169 - [2] [watchTowr Labs - We Spent $20 To Achieve RCE And Accidentally Became The Admins Of .MOBI](https://labs.watchtowr.com/we-spent-20-to-achieve-rce-and-accidentally-became-the-admins-of-mobi/)
    170 - [3] [RFC 3912 - WHOIS Protocol Specification](https://www.rfc-editor.org/rfc/rfc3912)
    171 - [4] [Nmap NSE documentation - `whois-ip`](https://nmap.org/nsedoc/scripts/whois-ip.html)
    172 - [5] [WHOIS Right? An Analysis of WHOIS and RDAP Consistency](https://arxiv.org/abs/2406.02046)