GO KALI FREE
IntermediateNetworking

Internet Infrastructure: DNS, WHOIS, and Domain Systems

Understand the core infrastructure of the internet including DNS hierarchy, WHOIS databases, Regional Internet Registries, and how domain names are managed globally.

#DNS#WHOIS#Internet#Infrastructure#Networking#Domain Names

How the Internet's Naming System Works

Every time you visit a website, a complex global infrastructure translates human-readable domain names into machine-readable IP addresses. Understanding this infrastructure is essential for network security, reconnaissance, and troubleshooting.

The DNS Hierarchy

Root Servers

The DNS hierarchy starts at the root, managed by 13 logical root server clusters (A through M) operated by organizations like ICANN, NASA, and the Internet Systems Consortium.

# Query root servers directly
dig . NS +short

# Trace resolution from root
dig example.com +trace | head -20

Top-Level Domains (TLDs)

TLDs are managed by registries under ICANN oversight:

  • **Generic TLDs** (.com, .net, .org) — Managed by Verisign and other registries
  • **Country-code TLDs** (.uk, .de, .jp) — Managed by national authorities
  • **New TLDs** (.app, .dev, .tech) — Introduced since 2012
  • Second-Level Domains

    Individual domains like "example" in "example.com" are registered through accredited registrars.

    WHOIS Infrastructure

    ICANN's Role

    ICANN (Internet Corporation for Assigned Names and Numbers) coordinates the global DNS system:

  • Maintains the root zone
  • Accredited registrars for gTLDs
  • Oversees WHOIS policy through RDAP
  • Manages the IANA functions
  • Regional Internet Registries (RIRs)

    Five RIRs manage IP address allocation globally:

    | RIR | Region | WHOIS Server |

    |-----|--------|--------------|

    | ARIN | North America | whois.arin.net |

    | RIPE NCC | Europe, Middle East, Central Asia | whois.ripe.net |

    | APNIC | Asia Pacific | whois.apnic.net |

    | LACNIC | Latin America and Caribbean | whois.lacnic.net |

    | AFRINIC | Africa | whois.afrinic.net |

    # Query specific RIR WHOIS servers
    whois -h whois.arin.net "n 8.8.8.8"
    whois -h whois.ripe.net 8.8.8.8
    

    WHOIS vs RDAP

    The Registration Data Access Protocol (RDAP) is replacing WHOIS:

  • **WHOIS** — Plain text, no standard format, limited search
  • **RDAP** — JSON-based, standardized, supports internationalized text
  • **Transition** — ICANN is gradually migrating to RDAP
  • Domain Registration Process

    How Domains Get Registered

  • **User searches** — Checks availability through a registrar
  • **Registrar queries** — Checks with the registry for the TLD
  • **Registration** — If available, registrar creates the domain record
  • **Registry update** — Registry updates the TLD zone file
  • **Propagation** — DNS servers worldwide receive the update
  • WHOIS Record Creation

    When a domain is registered, the WHOIS record includes:

  • Domain name and ID
  • Registrar information
  • Registration and expiration dates
  • Name servers
  • Registrant contact (often redacted post-GDPR)
  • Domain status codes
  • DNS Record Types Explained

    Core Records

    | Record | Purpose | Example |

    |--------|---------|---------|

    | A | Maps domain to IPv4 | example.com → 93.184.216.34 |

    | AAAA | Maps domain to IPv6 | example.com → 2606:2800:220:1::248 |

    | CNAME | Creates alias | www.example.com → example.com |

    | MX | Directs email | example.com → mail.example.com |

    | NS | Delegates DNS | example.com → ns1.example.com |

    | SOA | Zone metadata | Start of Authority data |

    Extended Records

    | Record | Purpose |

    |--------|---------|

    | TXT | Arbitrary text (SPF, DKIM, verification) |

    | SRV | Service location |

    | PTR | Reverse DNS lookup |

    | CAA | Certificate Authority Authorization |

    | DNSKEY | DNSSEC public key |

    | DS | Delegation Signer |

    DNS Resolution Process

    How a Domain Resolves

    1. Browser checks local cache
    2. OS checks resolver cache
    3. Resolver queries root server → gets TLD server
    4. Resolver queries TLD server → gets authoritative NS
    5. Resolver queries authoritative NS → gets IP address
    6. Browser connects to IP address
    

    Tracing DNS Resolution

    # Full trace from root
    dig example.com +trace
    
    # Query each level manually
    dig . NS +short                    # Root servers
    dig com. NS +short                 # TLD servers
    dig example.com NS +short          # Authoritative servers
    dig @ns1.example.com example.com   # Final resolution
    

    Infrastructure Security Considerations

    DNS Security

  • **DNS spoofing** — Attackers redirect DNS responses
  • **Cache poisoning** — Corrupt resolver cache with false records
  • **Zone transfers** — Misconfigured servers expose full DNS data
  • **DNS hijacking** — Change domain's authoritative name servers
  • ###防护措施

    # Enable DNSSEC
    # Configure in your registrar's control panel
    
    # Restrict zone transfers
    # Only allow authorized secondary DNS servers
    
    # Use DNS over HTTPS (DoH) or DNS over TLS (DoT)
    # Encrypt DNS queries to prevent interception
    
    # Monitor DNS changes
    # Set up alerts for unauthorized modifications
    

    Network Reconnaissance Using Infrastructure Knowledge

    IP Address Investigation

    # Identify the network owner
    whois $(dig target.com A +short) | grep -E "NetRange|OrgName"
    
    # Find related IP ranges
    whois $(dig target.com A +short) | grep "CIDR"
    
    # Check for BGP relationships
    whois -h whois.radb.net -- "-i origin AS15169"
    

    ASN Discovery

    # Find ASN for an IP
    whois -h whois.cymru.com " -v 8.8.8.8"
    
    # Get all IP ranges for an ASN
    whois -h whois.radb.net -- "-i origin AS15169" | grep "^route:"
    

    Frequently Asked Questions

    How does DNS caching work?

    DNS resolvers cache responses for a period defined by the TTL (Time to Live) value in the DNS record. Lower TTLs mean faster updates but more queries.

    What is the difference between authoritative and recursive DNS?

    Authoritative DNS servers hold the actual DNS records for a domain. Recursive DNS servers (like 8.8.8.8) query authoritative servers on behalf of clients and cache the results.

    How do I check if a domain uses DNSSEC?

    Use dig example.com +dnssec or check with online validators like DNSViz or Verisign's DNSSEC debugger.

    Why are there 13 root server clusters?

    This is a historical limitation based on the original DNS packet size (512 bytes). Modern DNS uses anycast to distribute root servers globally while maintaining 13 logical addresses.

    How often does WHOIS data update?

    WHOIS data updates in real-time when a domain is modified. However, cached WHOIS responses from third-party services may be stale by hours or days.

    Frequently Asked Questions

    What is the DNS hierarchy?

    DNS is a hierarchical system: root servers (13 clusters) point to TLD servers (.com, .uk), which point to authoritative name servers for individual domains. Queries cascade down this hierarchy to resolve domain names to IP addresses.

    What is the difference between authoritative and recursive DNS?

    Authoritative DNS servers hold the actual DNS records for a domain. Recursive DNS servers (like 8.8.8.8) query authoritative servers on behalf of clients and cache results for faster subsequent lookups.

    Why are there 13 root server clusters?

    This is a historical limitation from the original 512-byte DNS packet size. Modern DNS uses anycast to distribute root servers globally while maintaining 13 logical addresses (A through M).

    What is the difference between WHOIS and RDAP?

    WHOIS is a plain-text protocol with no standard format. RDAP (Registration Data Access Protocol) is JSON-based, standardized, supports internationalized text, and is gradually replacing WHOIS under ICANN's direction.

    What are Regional Internet Registries (RIRs)?

    Five RIRs manage IP allocation globally: ARIN (North America), RIPE NCC (Europe/Middle East), APNIC (Asia Pacific), LACNIC (Latin America), and AFRINIC (Africa). They manage IP address blocks and ASN allocation.

    How does DNS caching work?

    DNS resolvers cache responses for a TTL (Time to Live) period defined in DNS records. Lower TTLs mean faster updates but more queries. Cache duration varies from minutes to days depending on configuration.

    What is DNSSEC and why is it important?

    DNSSEC adds cryptographic signatures to DNS records, preventing DNS spoofing and cache poisoning. It validates that DNS responses come from authoritative sources and haven't been tampered with in transit.

    How do you trace DNS resolution?

    Use `dig example.com +trace` to see the full resolution path from root servers through TLD servers to authoritative name servers. This reveals the complete DNS infrastructure chain.