[Prev ] [Contents ] [Next ]
6.2.1 Whois Tool

You can search Whois data in ASTEC Eyes as follows;

  1. Open [Whois] dialog box.
  2. Specify Parameters and search Whois data.

Opening Whois Dialog Box

Procedure 1 (searching a specified host name)

Choose [Whois Tool...] from the [Tool] menu of the Main window.

Procedure 2 (searching with a Traffic window)

  1. Click a Graph Item or row for which you want to search a host name, in the Traffic window displaying IP addresses.
  2. Right-click on the window.
  3. Choose [Network Tools].
  4. Choose [Whois]. If more than one item is displayed, choose the host name or domain name you want to search.

Procedure 3 (searching with the Address Table or Address Book)

  1. Right-click on the row of the host you want to search in the IP Address Table, MAC - IP Address Table, or IP Address Book.
  2. Choose [Network Tools].
  3. Choose [Whois]. If more than one item is displayed, choose the host name or domain name you want to search.

Procedure 4 (search with the decode or stream view)

  1. Right-click on a packet or record containing an IP address in a decode or stream view.
  2. Choose [Network Tools].
  3. Choose [Whois]. If more than one item is displayed, choose the host name or domain name you want to search.

Configuring Whois Server, etc. and Searching

Procedure

  1. Enter a text into [Key] field of the [Whois] dialog box.
    If you open the [Whois] dialog box from a decode view, and so on, [Key] field is specified.
  2. Select a Whois server from the [Whois server] drop down combo box. In order to use a Whois server not in the list, enter the name into [Whois server] field.
  3. If you want connect to a Whois server through SOCKS server, select [Use SOCKS] check box and choose a SOCKS server.
    If there is not a SOCKS server you want to use in the list, click [Advanced...] button and
    configure a SOCKS server.
  4. Click [Run] button.
    Selecting [Print results on message window] will display the search results in the Message window of the Main window instead of [Result] region.

References


[Prev ] [Contents ] [Next ]