Whois footprinting is a reconnaissance technique used by attackers and penetration testers to gather publicly available information about domain names. By performing a Whois lookup, one can retrieve:
Domain registrant details (name, email, phone, and address)
Domain registration and expiry dates
Name servers and registrar information
Administrative and technical contact data
According to CEH v13:
Whois databases are maintained by Internet registrars and can be queried through tools like whois lookup or websites such as https://whois.domaintools.com.
This information helps attackers build a profile of the organization, identify potential social engineering targets, and even understand domain structure for further attacks.
Incorrect Options:
A. VPN footprinting refers to identifying VPN gateways or configurations — not related to domain data.
B. Email footprinting involves gathering information from or about email systems.
C. VoIP footprinting targets IP-based telephony systems, such as SIP endpoints.
Reference – CEH v13 Official Courseware:
Module 02: Footprinting and Reconnaissance
Section: “WHOIS Footprinting”
Tools: Whois lookup tools, ICANN WHOIS, DomainTools