The Test (or the revision)

General

For your records management, you can use the following Word template as a guide:
http://www.securityskeptic.com/2014/12/a-template-to-document-your-dns-investigations.html

Please do not use any all-in-one webservice such as Robtex for this "exercise", even if it might seem very attractive to do so.

Please note that ALL cybercrime teachers at the Lower Saxony Police Academy must be classified as untrustworthy with respect to the questions below.

Questions

  1. What URI does the following hyperlink refer to: ftp://richard:stallman@ftp.gnu.org:2121?
  2. What kind of URL is the URL in the answer to question #1?
  3. What is the TLD in the URI in the answer to question #1?
  4. What is the URL of the website where ICANN (IANA function) lists the responsibilities for all global TLDs?
  5. What company/companies or organisation(s) is/are responsible for managing the TLD in the answer to question #1?
  6. What is the URL of the web-based WHOIS service of the company/organisation in the answer to question #4?
  7. What are the names of the name servers that are responsible for resolving the internet domain in the answer to question #1?
  1. What is the Domain Holder data for the internet domain in the answer to question #1? Help
    Hetzner does not serve WHOIS over web!
  1. Is this data plausible and/or is the organisation/person trustworthy?
  1. What is the Administrative Contact data for the internet domain in the answer to question #1?
  1. Is this data plausible and/or is the organisation/person trustworthy?
  1. When was the data at the company/organisation associated with the internet domain in the answer to question #1 last updated (date and time)?
  2. What is the Technical Contact data for the internet domain in the answer to question #1?
  1. Is this data plausible and/or is the organisation/person trustworthy?
  1. What is the Billing Contact data for the internet domain in the answer to question #1?
  1. Is this data plausible and/or is the organisation/person trustworthy?
  1. What are the IP addresses to which the names of these name servers refer? Help
    eToolz does not support IPv6.
  1. When was the zone file of the internet domain in the answer to question #1 last modified (date)?
  2. What email address was filed in the SOA Resource Record for the internet domain in the answer to question #1?
  3. When do the entries in the zone file for the internet domain in the answer to question #1 expire?
  4. What is the A Resource Record for the internet domain in the answer to question #1?
  1. What type of Resource Record is the entry "foobar.domain-investigation.net"? Help
    PS C:\Users\user> nslookup foobar.domain-investigation.net
  2. What is the AAAA Resource Record for the internet domain in the answer to question #1? Help
    eToolz does not support IPv6.
  3. What is the MX Resource Record for the internet domain in the answer to question #1 (name and/or IPv4 and/or IPv6 address)? Help
    eToolz does not support IPv6.
  1. What is the difference between a domain name and a hostname?
  2. What is the URL of the website where the ICANN (IANA function) lists the responsibilities for all global IPv4 subnets?
  3. What is the URL of the website where the ICANN (IANA-function) lists the responsibilities for all global IPv6 subnets?
  4. What is the URL of the web-based WHOIS service of the company or organisation that is responsible for (re)assigning the IP address in the AAAA Resource Record for the internet domain in the answer to question #1?
  5. What is the"nic" handle for the organisation or person that reserved the IP address of the AAAA Records for the internet domain in answer #1 in its name?
  6. What is the data related to the "nic-hdl" searched previously?
  7. Is this data plausible and/or is the organisation/person trustworthy?
  8. What organisation or person reserved the IPv4 addresses of the A and/or MX Records for the internet domain in answer #1 in its name?
  9. Is this data plausible and/or is the organisation/person trustworthy?
  10. What is the ASN for the IP address (MX Resource Records) looked up last?
  11. What is the data of the "org" handle for the previously searched ASN?
  12. Is this data plausible and/or is the organisation/person trustworthy?
  13. If the email server of the internet domain in answer #1 it to be seized, what are the IPv4 and IPv6 addresses and the phone number of the person to contact?

Legend (tools required)

 grün  = web browser (domain-investigation.net, web WHOIS, ...)
 orange  = Windows eToolz desktop app
 rot  = command line (bash, cmd, ...)

Answers