Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
webrtc-ips — Demo: https://diafygi.github.io/webrtc-ips/ | Kitploit
Strumenti/GitHubGitHub/diafygi/webrtc-ips
OSINT (Open Source Intelligence)Web SecurityPrivacyLearning & Education
GitHubdiafygi/webrtc-ips

webrtc-ips

Demo: https://diafygi.github.io/webrtc-ips/

Vedi Repository
3.5k5882 anni faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

Richieste di indirizzi IP STUN per WebRTC

Demo: https://diafygi.github.io/webrtc-ips/

Cosa fa

Firefox e Chrome hanno implementato WebRTC, che consente di effettuare richieste a server STUN che restituiscono gli indirizzi IP locali e pubblici dell'utente. I risultati di queste richieste sono disponibili a JavaScript, quindi ora puoi ottenere gli indirizzi IP locali e pubblici di un utente in JavaScript. Questa demo è un esempio di implementazione di tutto ciò.

Inoltre, queste richieste STUN vengono effettuate al di fuori della normale procedura XMLHttpRequest, quindi non sono visibili nella console degli sviluppatori né possono essere bloccate da plugin come AdBlockPlus o Ghostery. Ciò rende questo tipo di richieste disponibile per il tracciamento online se un inserzionista configura un server STUN con un dominio wildcard.

Codice

Ecco la funzione demo commentata che effettua la richiesta STUN. Puoi copiarla e incollarla nella console sviluppatori di Firefox o Chrome per eseguire il test.

root@kitploit:~
//get the IP addresses associated with an account
function getIPs(callback){
    var ip_dups = {};

    //compatibility for firefox and chrome
    var RTCPeerConnection = window.RTCPeerConnection
        || window.mozRTCPeerConnection
        || window.webkitRTCPeerConnection;
    var useWebKit = !!window.webkitRTCPeerConnection;

    //bypass naive webrtc blocking using an iframe
    if(!RTCPeerConnection){
        //NOTE: you need to have an iframe in the page right above the script tag
        //
        //
        //<script>...getIPs called in here...
        //
        var win = iframe.contentWindow;
        RTCPeerConnection = win.RTCPeerConnection
            || win.mozRTCPeerConnection
            || win.webkitRTCPeerConnection;
        useWebKit = !!win.webkitRTCPeerConnection;
    }

    //minimal requirements for data connection
    var mediaConstraints = {
        optional: [{RtpDataChannels: true}]
    };

    var servers = {iceServers: [{urls: "stun:stun.services.mozilla.com"}]};

    //construct a new RTCPeerConnection
    var pc = new RTCPeerConnection(servers, mediaConstraints);

    function handleCandidate(candidate){
        //match just the IP address
        var ip_regex = /([0-9]{1,3}(\.[0-9]{1,3}){3}|[a-f0-9]{1,4}(:[a-f0-9]{1,4}){7})/
        var ip_addr = ip_regex.exec(candidate)[1];

        //remove duplicates
        if(ip_dups[ip_addr] === undefined)
            callback(ip_addr);

        ip_dups[ip_addr] = true;
    }

    //listen for candidate events
    pc.onicecandidate = function(ice){

        //skip non-candidate events
        if(ice.candidate)
            handleCandidate(ice.candidate.candidate);
    };

    //create a bogus data channel
    pc.createDataChannel("");

    //create an offer sdp
    pc.createOffer(function(result){

        //trigger the stun server request
        pc.setLocalDescription(result, function(){}, function(){});

    }, function(){});

    //wait for a while to let everything done
    setTimeout(function(){
        //read candidate info from local description
        var lines = pc.localDescription.sdp.split('\n');

        lines.forEach(function(line){
            if(line.indexOf('a=candidate:') === 0)
                handleCandidate(line);
        });
    }, 1000);
}

//Test: Print the IP addresses into the console
getIPs(function(ip){console.log(ip);});
Scarica lo strumento