Port 4321Referral Whois (RWhois)

Referral Whois (RWhois) is an extension of the traditional Whois protocol, designed to provide distributed and hierarchical management of network information, such as domain registrations and IP address allocations. It facilitates referrals to more specific registries responsible for the data, enabling a scalable infrastructure for querying network resources..

transport
tcp

single transport

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
4/10

caution

lookups
5,729

rank 856 of 993 · top 86%

Technical Details

what runs on :4321

Referral Whois (RWhois) protocol extends the classic Whois service to address scalability and delegation needs in an expanding Internet infrastructure. Traditional Whois is a flat, centralized database model maintained by registry authorities. RWhois introduces a hierarchical structure, allowing distributed databases maintained by multiple organizations responsible for various network resource allocations.

RWhois servers can refer query requests to other RWhois servers that hold more granular data. This referral system enables a query journey down the hierarchy, from broad registries to narrow, authoritative sources for specific information. It operates primarily over TCP port 4321 and uses a text-based query and response protocol similar to Whois, but includes support for structured object templates and referrals.

The protocol, while largely superseded by modern directory services and WHOIS replacements like RDAP, still aids certain legacy networking and registry functions. Its design aimed to accommodate delegation of resource management as the internet grew, minimizing centralized bottlenecks and easing administrative burdens.

Security Information

exposure of :4321

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

network services averages 3.9 across 604 ports — this one sits 0.1 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp

every listening transport is another surface to filter at the edge

security overview

Common Vulnerabilities:

  • Exposure of sensitive contact or registrant data through unsecured queries
  • Lack of encryption, making data susceptible to interception or man-in-the-middle attacks
  • Potential for information leakage aiding reconnaissance in cyberattacks
  • Misconfigurations leading to unauthorized access or unfiltered query results

Common Mitigations:

  • Restricting access to RWhois servers through IP whitelisting and query rate limiting
  • Implementing strong authentication mechanisms where possible
  • Using encrypted tunnels such as VPNs or SSH to protect data in transit
  • Regular audits of referral chains to prevent unauthorized data exposure
  • Considering migration to more secure and modern directory access protocols like RDAP, which support HTTPS encryption

the 8 most looked-up other ports in network services — 604 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted