Mapping the network
When you’re mapping out your network, you can search public databases
and resources to see what the hackers know about you.
Whois
The best starting point is to perform a Whois lookup by using any one of the
Whois tools available on the Internet. Whois is the tool you’ve most likely
used to check whether a particular Internet domain name is available.
For ethical hacking, Whois provides information that can give a hacker a leg
up to start a social-engineering attack or to scan your network:
- Internet domain-name information, such as contact names and addresses
- DNS servers responsible for your domain
You can look up Whois information at one of the following places:
- A domain registrar’s site, such as http://www.networksolutions.com or http://www.registerfly.com.
- An ISP’s tech-support page.
My favorite Whois tool is Sam Spade (www.samspade.org). You can use its
You can run DNS queries directly from the site or download the site’s Windowsbased
tool and run it from your PC. Sam Spade can
- Display general domain-registration information
- Show which host handles e-mail (the Mail Exchanger or MX record) for a domain
- Determine whether the host is listed on some spam blacklists

The following list runs down various lookup sites for other categories:
- Government: whois.nic.gov
- Military: whois.nic.mil
- AfriNIC: http://www.afrinic.org (emerging Regional Internet Registry for Africa)
- APNIC: http://www.apnic.net/search/index.html (Regional Internet Registry for the Asia Pacific Region)
- ARIN: http://www.arin.net/whois/index.html (Regional Internet Registry for North America, a portion of the Caribbean, and subequatorial Africa)
- LACNIC: Latin American and Caribbean Internet Addresses Registry http://www.lacnic.net
- RIPE Network Coordination Centre: http://www.ripe.net/db/whois/whois.html (Europe, Central Asia, African countries north of the equator, and the Middle East)
Alldomains.com offers a reverse Whois service called D-Tective. This paid
service finds specific Internet domains for a domain name, a phone number,
or an address.




