mirror of
https://github.com/rfc1036/whois.git
synced 2026-08-01 07:20:13 +00:00
WHOIS replies are written to the terminal without filtering control characters. A malicious server or on-path attacker can use escape sequences to manipulate the user's terminal. Sanitize text after character-set conversion and reject referrals with control characters before recursion. Sanitize referral status output as well, so the response and referral paths both preserve ISO-2022-JP conversion without passing terminal controls through.
In 1999 I wrote this Whois client from scratch because the alternatives were obsolete or bloated. This client is intelligent and can automatically select the appropriate whois server for most queries. The internal database is often more accurate than IANA's published one, but please send me any information you have regarding domains and network resources which are not correctly handled by the program. Because of historical reasons this package also contains the mkpasswd program, which can be used to encrypt a password with crypt(3). The canonical distribution point for releases of the program is https://ftp.debian.org/debian/pool/main/w/whois/ . Useful information sources: - https://www.ripe.net/ripe/docs/current-ripe-documents/ripe-database-documents - https://www.iana.org/domains/root/db/ - https://www.icann.org/en/resources/idn/fast-track/string-evaluation-completion - https://www.aftld.org/ Marco d'Itri <md@linux.it>
Description
Languages
C
79.5%
Roff
8.9%
Makefile
5.1%
Perl
4.2%
Shell
1.6%
Other
0.7%