Let's take an example IP from a business: (IP is random)
[root@kenji ~/]# whois -h whois.arin.net 74.95.180.0
#
# The following results may also be obtained via:
# http://whois.arin.net/rest/nets;q=74.95.180.0?showDetails=true&showARIN=false&ext=netref2
#
Comcast Business Communications, LLC CBC-PHILADELPHIA-33 (NET-74-95-160-0-1) 74.95.160.0 - 74.95.191.255
Comcast Business Communications, LLC CBC-CM-4 (NET-74-92-0-0-1) 74.92.0.0 - 74.95.255.255
What do we notice with my example? Comcast
Business Communications, What about normal Comcast cable users?
[root@kenji ~]# whois -h whois.arin.net 67.175.82.0
#
# The following results may also be obtained via:
# http://whois.arin.net/rest/nets;q=67.175.82.0?showDetails=true&showARIN=false&ext=netref2
#
Comcast Cable Communications, Inc. COMCAST (NET-67-160-0-0-1) 67.160.0.0 - 67.191.255.255
Comcast Cable Communications, Inc ILLINOIS-19 (NET-67-175-0-0-1) 67.175.0.0 - 67.175.127.255
Notice the differences? Now let's look at what Rel1k posts in his book:
[root@kenji ~/]# whois -h whois.arin.net 75.118.185.142
#
# The following results may also be obtained via:
# http://whois.arin.net/rest/nets;q=75.118.185.142?showDetails=true&showARIN=false&ext=netref2
#
WIDEOPENWEST OHIO WOW-CL11-1-184-118-75 (NET-75-118-184-0-1) 75.118.184.0 - 75.118.191.255
WideOpenWest Finance LLC WIDEOPENWEST (NET-75-118-0-0-1) 75.118.0.0 - 75.118.255.255
Most BUSINESSES will have their business information posted on the whois. We see none of this, alongside that statement, there is no indicator of any business name or secmaniac or maniac or sec or any other worthwhile identifier to state this IP space belongs to the author. So let's see who owns the IP space and what type of business they are in: WideOpenWest Finance LLC WIDEOPENWEST (NET-75-118-0-0-1) 75.118.0.0 - 75.118.255.255 Doesn't seem like a security company to me, its a cable provider (
http://www.wowway.com/).
Let's try this with Microsoft:
[root@kenji ~]# nslookup microsoft.com | sed -n '8p' | awk '{print "whois -h whois.arin.net "$2}' |sh|grep "^Org"|sort -u
OrgAbuseEmail: abuse@hotmail.com
OrgAbuseEmail: abuse@microsoft.com
OrgAbuseEmail: abuse@msn.com
OrgAbuseHandle: ABUSE231-ARIN
OrgAbuseHandle: HOTMA-ARIN
OrgAbuseHandle: MSNAB-ARIN
OrgAbuseName: Abuse
OrgAbuseName: Hotmail Abuse
OrgAbuseName: MSN ABUSE
OrgAbusePhone: +1-425-882-8080
OrgAbuseRef: http://whois.arin.net/rest/poc/ABUSE231-ARIN
OrgAbuseRef: http://whois.arin.net/rest/poc/HOTMA-ARIN
OrgAbuseRef: http://whois.arin.net/rest/poc/MSNAB-ARIN
OrgId: MSFT
OrgNOCEmail: noc@microsoft.com
OrgNOCHandle: ZM23-ARIN
OrgNOCName: Microsoft Corporation
OrgNOCPhone: +1-425-882-8080
OrgNOCRef: http://whois.arin.net/rest/poc/ZM23-ARIN
OrgName: Microsoft Corp
OrgTechEmail: iprrms@microsoft.com
OrgTechHandle: MSFTP-ARIN
OrgTechName: MSFT-POC
OrgTechPhone: +1-425-882-8080
OrgTechRef: http://whois.arin.net/rest/poc/MSFTP-ARIN
Notice two things 1) the information for the
COMPANY and 2) the
AMOUNT of information being returned. Most whois lookups will return
A LOT of information for companies whereas for most ISPs, the return will be a line or two long. That's first. The second thing to notice is the names of the business itself or the association with the domain you are looking up and the return information.
[root@kenji ~/]# whois -h whois.arin.net 96.126.127.220
#
# The following results may also be obtained via:
# http://whois.arin.net/rest/nets;q=96.126.127.220?showDetails=true&showARIN=false&ext=netref2
#
NetRange: 96.126.96.0 - 96.126.127.255
CIDR: 96.126.96.0/19
OriginAS:
NetName: LINODE-US
NetHandle: NET-96-126-96-0-1
Parent: NET-96-0-0-0-0
NetType: Direct Allocation
Comment: This block is used for static customer allocations.
RegDate: 2011-05-06
Updated: 2012-02-24
Ref: http://whois.arin.net/rest/net/NET-96-126-96-0-1
OrgName: Linode
OrgId: LINOD
Address: 329 E. Jimmie Leeds Road
Address: Suite A
City: Galloway
StateProv: NJ
PostalCode: 08205
Country: US
RegDate: 2008-04-24
Updated: 2010-08-31
Comment: http://www.linode.com
Ref: http://whois.arin.net/rest/org/LINOD
OrgNOCHandle: LNO21-ARIN
OrgNOCName: Linode Network Operations
OrgNOCPhone: +1-609-593-7103
OrgNOCEmail: support@linode.com
OrgNOCRef: http://whois.arin.net/rest/poc/LNO21-ARIN
OrgAbuseHandle: LAS12-ARIN
OrgAbuseName: Linode Abuse Support
OrgAbusePhone: +1-609-593-7103
OrgAbuseEmail: abuse@linode.com
OrgAbuseRef: http://whois.arin.net/rest/poc/LAS12-ARIN
OrgTechHandle: LNO21-ARIN
OrgTechName: Linode Network Operations
OrgTechPhone: +1-609-593-7103
OrgTechEmail: support@linode.com
OrgTechRef: http://whois.arin.net/rest/poc/LNO21-ARIN
RNOCHandle: LNO21-ARIN
RNOCName: Linode Network Operations
RNOCPhone: +1-609-593-7103
RNOCEmail: support@linode.com
RNOCRef: http://whois.arin.net/rest/poc/LNO21-ARIN
RTechHandle: LNO21-ARIN
RTechName: Linode Network Operations
RTechPhone: +1-609-593-7103
RTechEmail: support@linode.com
RTechRef: http://whois.arin.net/rest/poc/LNO21-ARIN
RAbuseHandle: LAS12-ARIN
RAbuseName: Linode Abuse Support
RAbusePhone: +1-609-593-7103
RAbuseEmail: abuse@linode.com
RAbuseRef: http://whois.arin.net/rest/poc/LAS12-ARIN
So who is this? What kind of company is it? I will let you answer this question now. It all boils down to power of logic and reasoning when unsure. You can i) Visit the website a whois returns to see more about the type of business associated with
the address and so forth.
This is
THE BIGGEST REASON that I am a stickler for understanding the common grounds of networking and systems before even attempting to venture out into security.