
Génère des adresses IP et des URL obfusquées à l'aide d'astuces DWORD, octales, hexadécimales, IPv6-mapped et de faux domaines @ pour les tests d'intrusion, la sensibilisation au phishing et les tests de filtrage d'URL.
Une boîte à outils de test de sécurité pour générer des adresses IP et des URL obfusquées. Utile pour les tests d'intrusion, la recherche en sécurité, la sensibilisation au phishing et le test des analyseurs/filtres d'URL.
Cette boîte à outils fournit deux interfaces :
ip_obfuscator.html - Interface graphique web pour une utilisation interactiveip_obfuscator.py - Outil en ligne de commande pour le scripting et l'automatisationLes deux outils génèrent les mêmes techniques d'obfuscation, notamment :
@)ip_obfuscator.html)Ouvrez ip_obfuscator.html dans n'importe quel navigateur moderne. Aucun serveur requis.
192.168.1.100)@ (par exemple, secure.bank.com)ip_obfuscator.py)# Show all obfuscation formats for an IP
python3 ip_obfuscator.py 192.168.1.100
# Generate obfuscated URLs
python3 ip_obfuscator.py 192.168.1.100 --url
# With fake domain and path
python3 ip_obfuscator.py 192.168.1.100 --url --fake-domain secure.bank.com --path /login
| Option | Courte | Description |
|---|---|---|
--url | -u | Générer des URL complètes au lieu de simples formats IP |
--fake-domain | -f | Faux domaine pour l'astuce @ (par défaut : google.com) |
--fake-pass | -w | Faux mot de passe pour le format user:pass@host |
--path | -p | Chemin de l'URL (par défaut : /) |
--port | -P | Numéro de port |
--https | -s | Utiliser HTTPS au lieu de HTTP |
--json | -j | Sortie au format JSON |
--filter | -F | Filtrer les résultats par mot-clé |
--list | -l | Sortie en liste compacte (valeurs uniquement) |
--zones | -z | Analyser les implications des zones de sécurité Windows |
--decode | -d | Décoder une IP obfusquée vers sa forme standard |
python3 ip_obfuscator.py 192.168.1.100 --url --fake-domain secure.bank.com --path /login
Sortie :
================================================================================
OBFUSCATED URL GENERATOR
================================================================================
Target IP: 192.168.1.100
Fake Domain: secure.bank.com
Fake Password: (none)
Port: (default)
Path: /login
Protocol: HTTP
================================================================================
DWORD/INTEGER FORMATS
--------------------------------------------------------------------------------
Standard (no obfuscation):
http://192.168.1.100/login
Decimal DWORD:
http://3232235876/login
Hex DWORD:
http://0xC0A80164/login
Octal DWORD:
http://030052000544/login
...
python3 ip_obfuscator.py 192.168.1.100 --url --fake-domain secure.bank.com --filter "fake auth" --json
Sortie :
{
"Fake Auth + Decimal DWORD": "http://secure.bank.com@3232235876/",
"Fake Auth + Hex DWORD": "http://secure.bank.com@0xc0a80164/",
"Fake Auth + Octal DWORD": "http://secure.bank.com@030052000544/",
"Fake Auth + Dotted Hex": "http://[email protected]/",
"Fake Auth + Dotted Octal": "http://[email protected]/",
"Fake Auth + IPv6 Mapped (hex)": "http://secure.bank.com@[::ffff:c0a8:164]/",
"Fake Auth + IPv6 Mapped (decimal)": "http://secure.bank.com@[::ffff:192.168.1.100]/",
"Fake Auth + IPv6 Mapped (full)": "http://secure.bank.com@[0000:0000:0000:0000:0000:ffff:c0a8:0164]/",
"Fake Auth + Class B": "http://[email protected]/",
"Fake Auth + Class C": "http://[email protected]/"
}
python3 ip_obfuscator.py 192.168.1.100 --url --https --filter ipv6
python3 ip_obfuscator.py 192.168.1.100 --list --filter ipv6
Sortie :
All obfuscated forms of 192.168.1.100:
::ffff:192.168.1.100
::ffff:c0a8:164
0000:0000:0000:0000:0000:ffff:c0a8:0164
0:0:0:0:0:ffff:c0a8:164
::ffff:c0a80164
::192.168.1.100
::c0a8:164
[::ffff:c0a8:164]
[::ffff:192.168.1.100]
[0000:0000:0000:0000:0000:ffff:c0a8:0164]
python3 ip_obfuscator.py --decode "http://secure.bank.com@3232235876/login"
Sortie :
Input: http://secure.bank.com@3232235876/login
Decoded: 192.168.1.100
python3 ip_obfuscator.py 192.168.1.100 --zones
Sortie :
================================================================================
MICROSOFT SECURITY ZONES ANALYSIS
================================================================================
The 'Dot Rule' (PlainHostName rule):
• Hostname WITHOUT dots → Local Intranet Zone
• Hostname WITH dots → Internet Zone
⚠️ SECURITY IMPACT of Intranet Zone:
• Automatic NTLM/Kerberos credential release (credential theft!)
• Less restrictive ActiveX/script policies
• May bypass security prompts and Mark-of-the-Web
================================================================================
Target IP: 192.168.1.100
================================================================================
🔴 DOTLESS → LOCAL INTRANET ZONE (HIGH RISK - credential leak)
--------------------------------------------------------------------------------
Decimal DWORD
URL: http://3232235876/
Note: CONFIRMED: MS98-016 specifically documents this as Intranet Zone bypass
Hex DWORD (0x prefix)
URL: http://0xC0A80164/
Note: CONFIRMED: Numeric hostname without dots → Intranet Zone
Octal DWORD
URL: http://030052000544/
Note: Octal integer without dots → Intranet Zone
🟢 DOTTED → INTERNET ZONE (normal security)
--------------------------------------------------------------------------------
Standard Dotted Decimal
URL: http://192.168.1.100/
Dotted Hex
URL: http://0xC0.0xA8.0x1.0x64/
...