43-pentesting-whois.md (8664B)
1 --- 2 title: "43 - Pentesting WHOIS" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/43-pentesting-whois.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/43-pentesting-whois.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 43 - Pentesting WHOIS 14 15 ## Basic Information 16 17 The **WHOIS** protocol provides text-based queries for information about Internet resources, including domain names, IP address blocks, and autonomous systems. The data model and query syntax are service-specific; RFC 3912 standardizes only the simple transport exchange.<sup>[[3]](#references)</sup> 18 19 **Default port:** 43 20 21 ```text 22 PORT STATE SERVICE 23 43/tcp open whois? 24 ``` 25 26 From an offensive point of view, remember that **WHOIS is a plain-text TCP service**: the client sends a query terminated by CRLF, the server returns text, and the **connection close marks the end of the response**. The protocol has no built-in authentication, integrity, or confidentiality.<sup>[[3]](#references)</sup> 27 28 ### Modern Reality: WHOIS vs RDAP 29 30 For Internet domain registration data, **WHOIS is no longer the authoritative option for many public gTLD workflows**. ICANN sunset WHOIS for gTLD registration data on **2025-01-28**, making **RDAP** the protocol to prefer for machine-readable domain registration lookups.<sup>[[1]](#references)</sup> 31 32 However, TCP/`43` is still worth testing because it keeps appearing in: 33 34 - **Legacy or private WHOIS services** 35 - **RIR / IP allocation workflows** 36 - **Internal registries and custom asset databases** 37 - **Third-party web tools and old automation** that still trust WHOIS responses 38 39 If your goal is **reverse whois**, broader asset expansion, or recursive external recon, check [the External Recon Methodology page](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/external-recon-methodology/README.md) to avoid duplicating work here. 40 41 ## Enumerate 42 43 Get all the information that a whois service has about a domain: 44 45 ```bash 46 whois -h <HOST> -p <PORT> "domain.tld" 47 printf 'domain.tld\r\n' | nc -vn <HOST> <PORT> 48 ``` 49 50 If you find a public-facing WHOIS service, test both **domain** and **IP/ASN** style queries because many implementations expose different backends or parsers depending on the object type: 51 52 ```bash 53 # Domain 54 printf 'example.com\r\n' | nc -vn <HOST> 43 55 56 # IP / CIDR / ASN examples 57 printf '8.8.8.8\r\n' | nc -vn <HOST> 43 58 printf 'AS15169\r\n' | nc -vn <HOST> 43 59 ``` 60 61 Sometimes a WHOIS response identifies the database or upstream registry being queried: 62 63  64 65 ### Referral Chasing and Better Enumeration 66 67 Useful WHOIS enumeration is often hidden behind **referrals**. One server may only identify the next authoritative service for a TLD or RIR. Test referral handling manually because custom clients and gateways can redact fields inconsistently or expose backend metadata.<sup>[[4]](#references)</sup> 68 69 Useful options and helpers: 70 71 ```bash 72 # Ask IANA first and then follow the authoritative referral (common Linux whois clients) 73 whois -I example.com 74 whois -I 8.8.8.8 75 76 # Let Nmap follow domain/IP WHOIS referrals automatically 77 nmap --script whois-domain <target> 78 nmap --script whois-ip <target> 79 80 # For IP ranges, disable the WHOIS cache if you care about smaller delegated blocks 81 nmap --script whois-ip --script-args whois.whodb=nocache <target> 82 ``` 83 84 Interesting fields to pivot on when the service is not fully redacted: 85 86 - **Registrar / Org / abuse contact** for phishing reporting or org-mapping 87 - **Creation / update / expiration times** to spot newly registered infrastructure 88 - **Nameservers** to cluster domains managed by the same operator 89 - **Referral server names** to find legacy or forgotten WHOIS infrastructure 90 91 ### RDAP as the Structured Successor 92 93 Even if the exposed service is classic WHOIS on port `43`, check whether the same provider also offers **RDAP** because RDAP is often easier to parse and better for automation: 94 95 ```bash 96 curl -s https://www.rdap.net/domain/example.com | jq 97 curl -s https://rdap.arin.net/registry/ip/8.8.8.8 | jq 98 ``` 99 100 A 2024 measurement study comparing WHOIS and RDAP at scale found that they are **not always interchangeable**, with inconsistencies in fields such as registrar identifiers, creation dates, and nameservers. If a recon pipeline depends on those values, compare both sources before making decisions.<sup>[[5]](#references)</sup> 101 102 ## Offensive Notes 103 104 ### Backend Injection in Custom WHOIS Gateways 105 106 Custom WHOIS gateways commonly query a registry database or proxy another directory. If input is concatenated into a backend query, **SQL injection** or another injection class may be possible. For example, an authorized lab test might send `whois -h 10.10.10.155 -p 43 "a') or 1=1#"`; this is an implementation flaw, not a property of the WHOIS protocol. 107 108 Do not limit testing to SQLi. In internal or niche WHOIS deployments, the query can be proxied to: 109 110 - SQL / NoSQL backends 111 - LDAP directories 112 - shell wrappers around other lookup tools 113 - HTTP APIs used by registrar or asset-management portals 114 115 So fuzz with payloads for **SQLi**, **LDAP injection**, delimiter abuse, very long strings, and malformed UTF-8 / control characters. The protocol itself is simple; the dangerous part is usually the **parser or backend glue code**. 116 117 ### Rogue / Stale WHOIS Servers 118 119 A relevant 2024-2025 attack path is abusing **outdated WHOIS trust**. If a registry or tool changes its WHOIS hostname and the old domain expires, an attacker may be able to register the old hostname and operate a **rogue WHOIS server**.<sup>[[2]](#references)</sup> 120 121 That gives the attacker control over the response body seen by: 122 123 - old WHOIS clients with hardcoded server mappings 124 - web applications that fetch WHOIS output and render it back to users 125 - automation that still uses WHOIS for domain validation or ownership workflows 126 127 This matters because a rogue WHOIS response can become an entry point for: 128 129 - **stored/reflected XSS** in web WHOIS frontends 130 - **parser bugs / command injection / eval bugs** in libraries consuming the text response 131 - **bad automation decisions** when systems trust attacker-controlled WHOIS contact data 132 133 When you find a private or legacy WHOIS service, always check whether the returned `refer:` / `Whois Server:` values, banners, or TLD mappings point to **expired or attacker-registerable domains**. 134 135 ## Shodan 136 137 - `port:43 whois` 138 139 ## HackTricks Automatic Commands 140 141 ```yaml 142 Protocol_Name: WHOIS #Protocol Abbreviation if there is one. 143 Port_Number: 43 #Comma separated if there is more than one. 144 Protocol_Description: WHOIS #Protocol Abbreviation Spelled out 145 146 Entry_1: 147 Name: Notes 148 Description: Notes for WHOIS 149 Note: | 150 The WHOIS protocol serves as a standard method for inquiring about the registrants or holders of various Internet resources through specific databases. These resources encompass domain names, blocks of IP addresses, and autonomous systems, among others. Beyond these, the protocol finds application in accessing a broader spectrum of information. 151 152 153 https://book.hacktricks.wiki/en/network-services-pentesting/43-pentesting-whois.html 154 155 Entry_2: 156 Name: Banner Grab 157 Description: Grab WHOIS Banner 158 Command: whois -h {IP} -p 43 {Domain_Name} && printf '{Domain_Name}\r\n' | nc -vn {IP} 43 159 160 Entry_3: 161 Name: Nmap WHOIS Referrals 162 Description: Follow WHOIS referrals for domain and IP lookups 163 Command: nmap --script whois-domain,whois-ip --script-args whois.whodb=nocache {IP} 164 ``` 165 166 ## References 167 168 - [1] [ICANN Update: Launching RDAP; Sunsetting WHOIS](https://www.icann.org/en/announcements/details/icann-update-launching-rdap-sunsetting-whois-27-01-2025-en) 169 - [2] [watchTowr Labs - We Spent $20 To Achieve RCE And Accidentally Became The Admins Of .MOBI](https://labs.watchtowr.com/we-spent-20-to-achieve-rce-and-accidentally-became-the-admins-of-mobi/) 170 - [3] [RFC 3912 - WHOIS Protocol Specification](https://www.rfc-editor.org/rfc/rfc3912) 171 - [4] [Nmap NSE documentation - `whois-ip`](https://nmap.org/nsedoc/scripts/whois-ip.html) 172 - [5] [WHOIS Right? An Analysis of WHOIS and RDAP Consistency](https://arxiv.org/abs/2406.02046)