02.11.2014 Views

untangling_the_web

untangling_the_web

untangling_the_web

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

DOClD: 4046925<br />

UNCLASSIFIEDNFOR OFF'lel~L US! ONLY<br />

Look for Additional Domains in Whois Database<br />

As an example, Kaspersky Labs owns and operates <strong>web</strong>sites under <strong>the</strong> domain<br />

names kaspersky-Iabs and avp (for Anti-Virus Protection) for many country top-level<br />

domains as well as <strong>the</strong> .com and .net domains. How did I find <strong>the</strong>se alternate<br />

domain names and <strong>web</strong>sites? By investigating Whois data on Kaspersky Labs and<br />

noting email addresses@avp.ruando<strong>the</strong>rservernames(kaspersky.com.<br />

kasperskylabs.net, kaspersky-Iabs. com ).<br />

Correlate Whois Data<br />

For example, when you find a person's name (<strong>the</strong> person object is <strong>the</strong> technical or<br />

administrative contact for a Whois entry), I suggest you search on that name in all<br />

<strong>the</strong> major Whois databases to see if his/her name shows up anywhere else, thus<br />

providing possible leads to relationships between seemingly unrelated companies or<br />

organizations. To see how this works, search on <strong>the</strong> name [vladimir] in <strong>the</strong> RIPE,<br />

ARIN, and APNle databases at IP-Plus:<br />

SE RVICES OPTIONS O UR NET WORK TECHNICAL INFO !ffiD' CUSTOME R CARE<br />

. :(.1 " @4 "S'I:t o z 11$, JfUi o ' · II Whl j" " 1 3.1 "i, M. ib'4A"Mi- e'lrow' U·j j Gfi3:" P V''''''ijl 1 ir-'''' h P<br />

s ~ l ncp~<br />

solu tic ns<br />

• S H o n d a ~ ' DUS<br />

+ Che d

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!