Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
webrtc-ips — Demo: https://diafygi.github.io/webrtc-ips/ | Kitploit
أدوات/GitHubGitHub/diafygi/webrtc-ips
OSINT (Open Source Intelligence)Web SecurityPrivacyLearning & Education
GitHubdiafygi/webrtc-ips

webrtc-ips

Demo: https://diafygi.github.io/webrtc-ips/

عرض المستودع
3.5k588منذ 2 سنواتتمت المراجعة من قبل Kitploit

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

طلبات عنوان IP الخاصة بـ STUN من أجل WebRTC

العرض التجريبي: https://diafygi.github.io/webrtc-ips/

ما الذي يفعله هذا

نفّذ كل من Firefox وChrome تقنية WebRTC التي تسمح بإرسال طلبات إلى خوادم STUN لتعيد عناوين IP المحلية والعامة للمستخدم. نتائج هذه الطلبات متاحة لجافاسكربت، لذا يمكنك الآن الحصول على عناوين IP المحلية والعامة للمستخدم في جافاسكربت. هذا العرض التجريبي هو تطبيق مثال على ذلك.

بالإضافة إلى ذلك، تُنفَّذ طلبات STUN هذه خارج إجراءات XMLHttpRequest العادية، لذلك لا تظهر في وحدة تحكم المطور ولا يمكن حظرها بواسطة إضافات مثل AdBlockPlus أو Ghostery. وهذا يجعل هذا النوع من الطلبات متاحًا للتتبع عبر الإنترنت إذا قام معلن بإعداد خادم STUN بنطاق بدل (wildcard).

الكود

في ما يلي الدالة التجريبية المشروحة التي تنشئ طلب STUN. يمكنك نسخ هذا ولصقه في وحدة تحكم المطور في Firefox أو Chrome لتشغيل الاختبار.

root@kitploit:~
//get the IP addresses associated with an account
function getIPs(callback){
    var ip_dups = {};

    //compatibility for firefox and chrome
    var RTCPeerConnection = window.RTCPeerConnection
        || window.mozRTCPeerConnection
        || window.webkitRTCPeerConnection;
    var useWebKit = !!window.webkitRTCPeerConnection;

    //bypass naive webrtc blocking using an iframe
    if(!RTCPeerConnection){
        //NOTE: you need to have an iframe in the page right above the script tag
        //
        //
        //<script>...getIPs called in here...
        //
        var win = iframe.contentWindow;
        RTCPeerConnection = win.RTCPeerConnection
            || win.mozRTCPeerConnection
            || win.webkitRTCPeerConnection;
        useWebKit = !!win.webkitRTCPeerConnection;
    }

    //minimal requirements for data connection
    var mediaConstraints = {
        optional: [{RtpDataChannels: true}]
    };

    var servers = {iceServers: [{urls: "stun:stun.services.mozilla.com"}]};

    //construct a new RTCPeerConnection
    var pc = new RTCPeerConnection(servers, mediaConstraints);

    function handleCandidate(candidate){
        //match just the IP address
        var ip_regex = /([0-9]{1,3}(\.[0-9]{1,3}){3}|[a-f0-9]{1,4}(:[a-f0-9]{1,4}){7})/
        var ip_addr = ip_regex.exec(candidate)[1];

        //remove duplicates
        if(ip_dups[ip_addr] === undefined)
            callback(ip_addr);

        ip_dups[ip_addr] = true;
    }

    //listen for candidate events
    pc.onicecandidate = function(ice){

        //skip non-candidate events
        if(ice.candidate)
            handleCandidate(ice.candidate.candidate);
    };

    //create a bogus data channel
    pc.createDataChannel("");

    //create an offer sdp
    pc.createOffer(function(result){

        //trigger the stun server request
        pc.setLocalDescription(result, function(){}, function(){});

    }, function(){});

    //wait for a while to let everything done
    setTimeout(function(){
        //read candidate info from local description
        var lines = pc.localDescription.sdp.split('\n');

        lines.forEach(function(line){
            if(line.indexOf('a=candidate:') === 0)
                handleCandidate(line);
        });
    }, 1000);
}

//Test: Print the IP addresses into the console
getIPs(function(ip){console.log(ip);});
تنزيل الأداة