DEF CON Forum Site Header Art

Announcement

Collapse
No announcement yet.

DOMAIN OWNER LOOKUP

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Question: DOMAIN OWNER LOOKUP

    Is there any ways, i can see the owner of a website or domain? Tried WHOIS but it didn't give me names. Thank You!

  • #2
    Originally posted by babayaga View Post
    Is there any ways, i can see the owner of a website or domain? Tried WHOIS but it didn't give me names. Thank You!
    Explaining this for everyone, not just you:

    Domain registration is primarily done under a "Top Level Domain" (TLD) such as ".com" or ".net" or ".mil" or ".int" or ".org" or "gov" or country codes like ".ca" though for some top level domains they sometimes have one or more levels of delegation, like was attempted with the ".us" and having a 2 letter state code like ".ca.us" for "California" in the "United States" or ".co.uk." in the U.K.

    After domain regsitration, the "owner" of a domain can create one or more "Fully Qualified Domain Names" (FQDN) or even delegate a "sub domain" to be managed by another server.

    For example, if you want to know about the "domain" "www.updates.microsoft.com" if we assume it existed as a real name, in this case the TLD is ".com" so the domain name is "microsoft.com" and that is what you would use to ask a registrar about the owner... the domain "microsoft.com" ... the "www.updates." would be additions in DNS either as a FQDN or a FQDN under a subdomain.

    Next, some places provide domain registration by proxy, or provide an alias to limit public access to the details of the real owner of a domain.

    Let's assume the domain you are interested in learning about doesn't have a registration by proxy. Let's consider the above example.

    If you visit your favorite search engine and ask "whois lookup" you should be presented with several options.

    I tried godaddy whois search https://www.godaddy.com/offers/whois-b , but it didn't show contact information.

    When I visit https://lookup.icann.org/ , and I typed "microsoft.com"

    that server provides these results:
    Domain Information
    Name: MICROSOFT.COM
    Registry Domain ID: 2724960_DOMAIN_COM-VRSN
    Domain Status:
    clientDeleteProhibited
    clientTransferProhibited
    clientUpdateProhibited
    serverDeleteProhibited
    serverTransferProhibited
    serverUpdateProhibited
    Nameservers:
    NS1-39.AZURE-DNS.COM

    NS2-39.AZURE-DNS.NET

    NS3-39.AZURE-DNS.ORG

    NS4-39.AZURE-DNS.INFO

    Dates
    Registry Expiration: 2024-05-03 04:00:00 UTC
    Updated: 2023-04-01 11:51:08 UTC
    Created: 1991-05-02 04:00:00 UTC​



    Contact Information
    Administrative:
    Handle: 181479
    Name: Domain Administrator
    Organization: Microsoft Corporation
    Email: admin@domains.microsoft
    Phone: +1.4258828080
    Fax: +1.4259367329
    Mailing Address: One Microsoft Way, Redmond, WA, 98052, US
    Registrant:
    Handle: 181479
    Name: Domain Administrator
    Organization: Microsoft Corporation
    Email: admin@domains.microsoft
    Phone: +1.4258828080
    Fax: +1.4259367329
    Mailing Address: One Microsoft Way, Redmond, WA, 98052, US
    Technical:
    Handle: 44299
    Name: MSN Hostmaster
    Organization: Microsoft Corporation
    Email: msnhst@microsoft.com
    Phone: +1.4258828080
    Fax: +1.4259367329
    Mailing Address: One Microsoft Way, Redmond, WA, 98052, US
    Registrar Information
    Name: MarkMonitor Inc.
    IANA ID: 292
    Abuse contact email: abusecomplaints@markmonitor.com
    Abuse contact phone: +1.2086851750
    As you can see, with this example, contact information is available. Not all domains provide this. Not all "whois" services provide answers for all TLD. Some may only provide whois information for .com, .net, and .org. Not all whois servers handle all charactersets, and some will fail with multibyte charactersets such at those that use punycode to represent multibyte charactersets by encoding in ASCII limited 7-bit characters valid for DNS hostnames. (See: https://en.wikipedia.org/wiki/Punycode for details.) Some whois service lookups have trouble encoding multibute responses in fields for reading in native language, resulting in strange symbols that are not at all like what would be expected shown if the real characters were to be displayed.

    Some whois server limit the information they relay. I tested a godaddy whois service lookup for microsoft.com and it did not include any of the contact information or abuse details for abuse reporting like the icann lookup.

    Not all whois clients provide the same results.

    Not all whois server provide the same results.

    Most "whois" servers have restrictions on their use. Most have checks to see if you are using their service "too much" and then will block your access.
    The primary purpose with whois information with domains was to get a technical or abuse contact, so you could relay to them issues of abuse or technical issues their domain-name-zones or hosts are having.

    Be careful of any services offering lookups for money, or payment as many fee-based services that spam-advertise in forums like this are scammy.

    Good luck!
    Last edited by number6; 2 weeks ago.

    Comment

    Working...
    X