Chinaunix首页 | 论坛 | 博客
  • 博客访问: 19733338
  • 博文数量: 679
  • 博客积分: 10495
  • 博客等级: 上将
  • 技术积分: 9308
  • 用 户 组: 普通用户
  • 注册时间: 2006-07-18 10:51
文章分类

全部博文(679)

文章存档

2012年(5)

2011年(38)

2010年(86)

2009年(145)

2008年(170)

2007年(165)

2006年(89)

分类: 网络与安全

2008-03-12 09:37:57

14  网络侦察工具

介绍性的第一段不是很理解,留待以后阅读。

     WHOIS/FWHOIS

Windows可以通过Cygwin environment来使用whois,这个地方不解。Linux中通常使用bw-whois,但是redhat中好像依然是whois

格式:whois -h whois.alldomains.com yahoo.comlinux中可能为:bash% fwhois 。都表示要在whois.alldomains.com中查找。默认的查找服务器是: or .

 

查找实例:

whois sohu.com

[Querying whois.internic.net]

[Redirected to whois.networksolutions.com]

[Querying whois.networksolutions.com]

[whois.networksolutions.com]

NOTICE AND TERMS OF USE: You are not authorized to access or query our WHOIS

database through the use of high-volume, automated, electronic processes. The

Data in Network Solutions' WHOIS database is provided by Network Solutions for information

purposes only, and to assist persons in obtaining information about or related

to a domain name registration record. Network Solutions does not guarantee its accuracy.

By submitting a WHOIS query, you agree to abide by the following terms of use:

You agree that you may use this Data only for lawful purposes and that under no

circumstances will you use this Data to: (1) allow, enable, or otherwise support

the transmission of mass unsolicited, commercial advertising or solicitations

via e-mail, telephone, or facsimile; or (2) enable high volume, automated,

electronic processes that apply to Network Solutions (or its computer systems). The

compilation, repackaging, dissemination or other use of this Data is expressly

prohibited without the prior written consent of Network Solutions. You agree not to use

high-volume, automated, electronic processes to access or query the WHOIS

database. Network Solutions reserves the right to terminate your access to the WHOIS

database in its sole discretion, including without limitation, for excessive

querying of the WHOIS database or for failure to otherwise abide by this policy.

Network Solutions reserves the right to modify these terms at any time.

 

Get a FREE domain name registration, transfer, or renewal with any annual hosting package

- or just $8.95 with monthly packages.

 

 

Visit AboutUs.org for more information about SOHU.COM

AboutUs: SOHU.COM

 

 

 

 

Registrant:

Sohu.com Limited

   11 Floor,

   No.1 Zhongguancun East Road. Vision Bld.

   BEIJING, BJ 100084

   CN

 

   Domain Name: SOHU.COM

 

   ------------------------------------------------------------------------

   Promote your business to millions of viewers for only $1 a month

   Learn how you can get an Enhanced Business Listing here for your domain name.

   Learn more at

   ------------------------------------------------------------------------

 

   Administrative Contact, Technical Contact:

      Li, Keyn          dnsadmin@sohu-inc.com

      SOHU.COM

      F10, Tech-NO

      Sohu Plaza.,No.1 Zhongguancun East Road.

      BEIJING, Beijing 100084

      CN

      8610-62728000 fax: 8610-62702152

 

 

   Record expires on 04-Jul-2009.

   Record created on 05-Jul-1998.

   Database last updated on 10-Mar-2008 21:34:04 EDT.

 

   Domain servers in listed order:

 

   NS1.SOHU.COM                 61.135.179.169

   NS2.SOHU.COM                 220.181.26.167

   NS3.SOHU.COM                 220.181.26.168

 

注意登记的时候一般不要使用真实名字。

 

根据IP来查找:

# whois 203.222.12.251

[Querying whois.apnic.net]

[whois.apnic.net]

% [whois.apnic.net node-1]

% Whois data copyright terms   

 

inetnum:      203.222.0.0 - 203.222.31.255

netname:      MONAD-TW

country:      TW

descr:        Monad Digitnamic Corp.

descr:        MAN provider

descr:        Taichung Taiwan R.O.C

admin-c:      BT144-AP

tech-c:       BT144-AP

status:       ALLOCATED PORTABLE

mnt-by:       APNIC-HM

mnt-lower:    MAINT-TW-MONAD

mnt-routes:   MAINT-TW-MONAD

changed:      hm-changed@apnic.net 20050627

changed:      hm-changed@apnic.net 20050628

source:       APNIC

 

person:       Brave Ting

nic-hdl:      BT144-AP

e-mail:       brave.ting@speed.net.tw

address:      21F No.6

address:      Ln256 Sec.2 Shih-tun Rd.

address:      Taichung

address:      Taiwan R.O.C.

phone:        +886-4-27086556 Ext.1601

fax-no:       +886-4-27018587

country:      TW

changed:      brave.ting@speed.net.tw 20050624

mnt-by:       MAINT-TW-MONAD

source:       APNIC

 

        可以看出这是台中的地址。

 

常用的查询地址:

Server

Purpose

Default whois servers—launching point for many other whois queries

New whois authority for .org domain names

Server for customers who registered their domain names with Network Solutions

Another popular domain name registration service

Yet another popular registrar

Server from the American Registry for Internet Numbers—does IP-based whois queries

Server for Asia Pacific Network Information Center Whois Database

Réseaux IP Européens—handles most of Europe

Russian Network Information Center (for .ru and .su)

U.S. Government whois server (for .gov)

Military (U.S. Department of Defense) whois server (for .mil)

 

 

      HOST, DIG, AND NSLOOKUP

这些文件一般在BIND包中,,可以查询域名信息和其他信息,比如mail handler for a specified domain

 

     WindowsNslookup

 

Nslookup

显示可用来诊断域名系统 (DNS) 基础结构的信息。使用此工具之前,您应当熟悉 DNS 的工作原理。只有在已安装 TCP/IP 协议的情况下才可以使用 Nslookup 命令行工具。

详细信息暂略

 

     Linux中的Nslookuphost dig

Nslookup host功能类似,将会被host取代。

#  nslookup -silent

Server:         218.30.19.40

Address:        218.30.19.40#53

 

Non-authoritative answer:

Name:  

Address: 68.178.201.211

 

# host

has address 68.178.201.211

 

        host 使用-t可以指定类型,SOA用于指定从一级DNS更新的时间。同步过程叫做zone transfer安全起见,不允许随便同步。可以在named.conf allow-transfer 处配置。

 

# host -t mx antihackertoolkit.com

antihackertoolkit.com mail is handled by 0 smtp.secureserver.net.

antihackertoolkit.com mail is handled by 10 mailstore1.secureserver.net.

 # host -t soa antihackertoolkit.com

antihackertoolkit.com SOA ns2.zoneedit.com. soacontact.zoneedit.com. 1138303783 14400 7200 950400 7200

 

        dig可以显示的更加详细,暂略。比如:dig @got.wedgie.org wedgie.org axfr。它的查询格式可以参考:(). 还可以发现bind的版本号:dig @got.wedgie.org version.bind. txt chaos
 
 
阅读(7846) | 评论(1) | 转发(0) |
给主人留下些什么吧!~~

chinaunix网友2008-03-12 09:40:03

下一篇:http://blog.chinaunix.net/u/21908/showart.php?id=494250