Re: [weirds] I-D Action: draft-hollenbeck-dnrd-ap-query-00.txt

Andy Newton <andy@hxr.us> Tue, 01 May 2012 12:49 UTC

Return-Path: <andy@hxr.us>
X-Original-To: weirds@ietfa.amsl.com
Delivered-To: weirds@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2767D21E84D2 for <weirds@ietfa.amsl.com>; Tue, 1 May 2012 05:49:06 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.599
X-Spam-Level:
X-Spam-Status: No, score=-3.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id c4Xlv67xfyF3 for <weirds@ietfa.amsl.com>; Tue, 1 May 2012 05:49:05 -0700 (PDT)
Received: from mail-qc0-f172.google.com (mail-qc0-f172.google.com [209.85.216.172]) by ietfa.amsl.com (Postfix) with ESMTP id 6FE3521E84DA for <weirds@ietf.org>; Tue, 1 May 2012 05:49:05 -0700 (PDT)
Received: by qcsq13 with SMTP id q13so2236795qcs.31 for <weirds@ietf.org>; Tue, 01 May 2012 05:49:05 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=subject:mime-version:content-type:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to:x-mailer :x-gm-message-state; bh=IXqqSY1pHua1cOKNGeeQR2agEO+Isl8ELZfw2RJyuDY=; b=RG1Dg4NCQ8vmnj29NhO1ATrkpW4KQKIlAhF/Xk+VCSUjz0vh/ZJvVS7Dhir1qli72d 9SfcNxtAQ/NRaJ/hyiTeb/BkKvUzC6mcCkqRt1UHyur4b+KQ7yD/AUxxT0p4D/m5LEGt /zX3M5yMj2cSe8Ms25YMhJEPMEqAloiLDoBPqIaBKUP+U6pErR3+eHZchCcM3yJ9tLcu lQeshRdPbIAZObdGILMpgktDfTDC7iveW5aYRY7htfenhLLseikfJRdttkNfYcUO5lSP FmFaQNEZO6X1uw7IXWsJj2H9KzdaLoS7DOUi+D2pimJJhUkygvC+Z9DU5IX1dpqA4+nf l7TA==
Received: by 10.229.137.12 with SMTP id u12mr6331915qct.156.1335876544855; Tue, 01 May 2012 05:49:04 -0700 (PDT)
Received: from andytop.arin.net (core.arin.net. [192.149.252.11]) by mx.google.com with ESMTPS id s20sm29827734qap.16.2012.05.01.05.49.03 (version=TLSv1/SSLv3 cipher=OTHER); Tue, 01 May 2012 05:49:03 -0700 (PDT)
Mime-Version: 1.0 (Apple Message framework v1257)
Content-Type: text/plain; charset="us-ascii"
From: Andy Newton <andy@hxr.us>
In-Reply-To: <6DAAECD8-30D3-4195-BE44-C95D0EE3ECE3@icann.org>
Date: Tue, 01 May 2012 08:49:02 -0400
Content-Transfer-Encoding: quoted-printable
Message-Id: <AC14FC70-A653-4204-9A78-E40AB68B3228@hxr.us>
References: <20120501024631.97808.qmail@joyce.lan> <6DAAECD8-30D3-4195-BE44-C95D0EE3ECE3@icann.org>
To: Dave Piscitello <dave.piscitello@icann.org>
X-Mailer: Apple Mail (2.1257)
X-Gm-Message-State: ALoCoQkgGhICdkwBptxiaGxa4KRTgwfkw881jK9IRkwJYfyWbDUBGgMNjkYXPrch4YhS8uMAJMZ7
Cc: John Levine <johnl@iecc.com>, "weirds@ietf.org" <weirds@ietf.org>
Subject: Re: [weirds] I-D Action: draft-hollenbeck-dnrd-ap-query-00.txt
X-BeenThere: weirds@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "WHOIS-based Extensible Internet Registration Data Service \(WEIRDS\)" <weirds.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/weirds>, <mailto:weirds-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/weirds>
List-Post: <mailto:weirds@ietf.org>
List-Help: <mailto:weirds-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/weirds>, <mailto:weirds-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 01 May 2012 12:49:06 -0000

On May 1, 2012, at 8:03 AM, Dave Piscitello wrote:

> +1
> 
> In a searchable world, sometimes all you have is the IP of the name server that's resolving the malicious/harmful domain. So asking "what other domains host zone files at this IP?", "who registered those domains?", and "what registrar is sponsoring the registrations?" are all useful crumbs that often help you identify names used by in a campaign, or the registrant names used in association with a criminal enterprise. 

Are you gonna hit up every registry or registrar in the world looking for your answer? I'm a little fuzzy on the use case.

And does this feature already exist in many registry Whois servers?

-andy