02.11.2014 Views

untangling_the_web

untangling_the_web

untangling_the_web

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

DID: 4046925<br />

UNCLA551FIEDffFOft OFFlelAL USE OP4L¥<br />

~ Network Whois lookup-input format: IP address<br />

IP address blocks are maintained by ARIN, RIPE, AfriNIC, LACNIC, and APNIC<br />

in separate, non-distributed databases. Formatted Whois data provides a wealth<br />

of registration information. All five Whois databases allow for advanced searches<br />

on fields o<strong>the</strong>r than IP address.<br />

~ Domain Name (Whois) lookup-input format: domain name<br />

Checks a domain name against registration records based upon that domain<br />

name's TLD (.com, .uk, .ru, etc.); some automated programs can search some or<br />

all domain name registries at once.<br />

The confusion about domain name and Whois lookups is probably in part caused by<br />

<strong>the</strong> fact that domain name registration is separate from IP address assignment.<br />

Perhaps <strong>the</strong> easiest way to understand this is to consider <strong>the</strong> following fictitious,<br />

overly simplistic example.<br />

An imaginary Russian company named Moscow Motors wants to register two<br />

domain names: moscowmotors.ru and moscowmotors.com. But Moscow Motors<br />

only wants to use one IP address through its ISP, RT Communications (RTComm)<br />

Network in Moscow. The European Registry, RIPE, maintains <strong>the</strong> block of IP<br />

addresses handled by RTComm. Next, Moscow Motors goes to Network Solutions,<br />

Inc., to register its moscowmotors.com domain name and to RU-Center, <strong>the</strong> Russian<br />

top-level domain name registration service, to register its moscowmotors.ru domain<br />

name. Both domain names resolve to <strong>the</strong> same IP address registered with RIPE.<br />

Now let's say a user runs a domain name lookup against moscowmotors.com. He<br />

finds <strong>the</strong> domain name is registered with Network Solutions, but when he tries to<br />

look up <strong>the</strong> corresponding IP address belonging to moscowmotors.com, he finds<br />

<strong>the</strong>re is no network Whois record in <strong>the</strong> American Registry (ARIN) Whois database.<br />

Why? Because <strong>the</strong> ARIN Whois database only contains IP addresses assigned to it,<br />

and moscowmotors.com resolves to an IP address in <strong>the</strong> European (RIPE)<br />

database.<br />

If you would like to see a real-life example of what I've just described, try <strong>the</strong><br />

following:<br />

1. Go to Domain Dossier (http://centralops.netlcolDomainDossier.vbs.asp) and<br />

enter <strong>the</strong> following query:<br />

ripe.net<br />

search on domain whois record and network whois record<br />

2. Look at <strong>the</strong> IP address for ripe.net: 193.0.0.203<br />

454 UNCLA551FIEDJlFOR OFFICIAL USE ONLY

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!