Identifying the ownership of a website

This is a quick step-by-step guide with the steps to follow to identify Internet web site coordinates (IP address, registration data, connectivity and name service provider).

Step 0 Download a copy of the website (if required for investigation purposes)

You can do that using wget, compressing using tar and gzip and finally keeping an md5 hash.
wget -m -k -K -E webname
tar -cf webname.tar *
gzip webname.tar (or get both steps together with tar -czvf webname.tar.gz)
md5sum webname.tar.gz > webname.tar.gz.md5

Step 1 Obtaining the IP address of the site (e.g. with www.google.com)
Launch a nslookup query (in Linux or Windows) to get the IP address of the site

$ nslookup www.google.com

An alternative to this command is

$ dig +qr www.google.com

There are many online sites providing online nslookup services e.g.
http://centralops.net/asp/co/NsLookup.vbs.asp
http://www.kloth.net/services/dig.php

If you need a name server IP address to bind to, some examples are

142.77.1.1
193.196.32.1
208.07.222.222
129.206.100.126
70.84.161.11

Step 2 Determine the owner of the IP address
Go to arin whois service and introduce the IP address from step 1 and you will read something like NetType: Allocated to RIPE NCC. The RIPE NCC is one of five Regional Internet Registries (RIRs) providing Internet resource allocations, registration services and co-ordination activities that support the operation of the Internet globally. Others are AfriNIC, APNIC, LACNIC, RIPE and InterNIC.

Step 3 Obtain the hosting company name
Go to the Internet register that the previous step signalled as owner of the IP range requested e.g. http://www.db.ripe.net/whois/ and insert the same IP address. You will get the hosting company.

Step 4 Name service provider
$ dig +qr www.website NS (ns in lower letters will also work - provides information on the authoritative name servers for that website)
Search on the Internet infomation on the name service (company name and contact point)
More on this command
$ dig +qr www.website MX (tells about the mail server associated to the site)
$ dig +qr www.website A (tells the IP address of the site)
$ dig +qr www.website ANY (provides a subset of the three commands above)

This step will tell us which authoritative name servers provides the name to the website (there are occasions when the name server provider differs from the hosting company).

N.B. Thanks to Melkiades for his help on this entry.

Security and risk blog

Welcome to this site about information security and risk management by Alberto Partida, an IT security professional.
Hacking is about outsmarting those who have designed the information system.
Information security is about outsmarting hacking.

These are the some of the topics discussed in Security and risk:
Current technical (or not) infosec topics
Enterprise risk management study
The 8 critical success actions for Infosec
Publications
Links to IS Security sites
Security papers

Enterprise risk management

How do companies face and manage risks currently? Do their diverse risk management functions still work in silos? Where does information security fit in this risk management puzzle? Among others, these questions are the triggers for an academic information security study that is presented in this site.

The study investigates how the link of information security with operational risk management brings benefits to any organisation. It has the following sections:

Executive summary
Introduction
Hypothesis
The risk house model
Outcome of the survey: Demographics
Outcome of the survey: Interpretation
Literature review: Thinking path
Literature references
Literature review: Summary
In a nutshell
Present and future
Annex: Link to the survey
Annex: Survey questions
Annex: Survey questions (Spanish)
Acknowledgements
Copyright
Awards


Information Systems Security sites

- Secure home pc: This site posts regularly articles on day-to-day topics related to endpoint computer security. It targets computer users that are not IT experts but, at the same time, would like to have a secure computer for their daily activities (email, banking, blogging, sharing, etc.).

Security papers

Practical paper about the 8 critical success actions for Information Security in the SANS Leadership Laboratory.

If you are interested on the presentation regarding the 8 critical success actions for an information security function, please leave a comment on this blog.

Paper on two forensic cases, hidden company files and a USB memory stick (submitted for the SANS GIAC Gold Forensic Analyst Certification).

Paper about the DMZ of a start-up (submitted for the SANS GIAC Gold Firewall Analyst Certification).

Paper on secure application development (submitted for the SANS GIAC Gold Security Essentials Certification).

Article on Blackberry deployment in SANS Advisor.

Paper on critical success factors in information security (co-author).