Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
webrtc-ips — デモ: https://diafygi.github.io/webrtc-ips/ | Kitploit
ツール/GitHubGitHub/diafygi/webrtc-ips
OSINT (オープンソースインテリジェンス)ウェブセキュリティプライバシー学習と教育
GitHubdiafygi/webrtc-ips

webrtc-ips

デモ: https://diafygi.github.io/webrtc-ips/

リポジトリを見る
3.5k588311年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

WebRTC 向け STUN IP アドレス要求

デモ: https://diafygi.github.io/webrtc-ips/

これは何をするか

Firefox と Chrome には、ユーザーのローカル IP アドレスとパブリック IP アドレスを返す STUN サーバーへの要求を可能にする WebRTC が実装されています。この要求の結果は JavaScript から利用できるため、JavaScript でユーザーのローカル IP アドレスとパブリック IP アドレスを取得できるようになりました。このデモは、その実装例です。

さらに、これらの STUN 要求は通常の XMLHttpRequest の手順の外で行われるため、開発者コンソールには表示されず、AdBlockPlus や Ghostery などのプラグインによってブロックされることもありません。これにより、広告主がワイルドカードドメイン付きの STUN サーバーを設定した場合、この種の要求がオンライントラッキングに利用可能になります。

コード

以下は、STUN 要求を行う注釈付きデモ関数です。これを Firefox または Chrome の開発者コンソールにコピー&ペーストしてテストを実行できます。

root@kitploit:~
//get the IP addresses associated with an account
function getIPs(callback){
    var ip_dups = {};

    //compatibility for firefox and chrome
    var RTCPeerConnection = window.RTCPeerConnection
        || window.mozRTCPeerConnection
        || window.webkitRTCPeerConnection;
    var useWebKit = !!window.webkitRTCPeerConnection;

    //bypass naive webrtc blocking using an iframe
    if(!RTCPeerConnection){
        //NOTE: you need to have an iframe in the page right above the script tag
        //
        //
        //<script>...getIPs called in here...
        //
        var win = iframe.contentWindow;
        RTCPeerConnection = win.RTCPeerConnection
            || win.mozRTCPeerConnection
            || win.webkitRTCPeerConnection;
        useWebKit = !!win.webkitRTCPeerConnection;
    }

    //minimal requirements for data connection
    var mediaConstraints = {
        optional: [{RtpDataChannels: true}]
    };

    var servers = {iceServers: [{urls: "stun:stun.services.mozilla.com"}]};

    //construct a new RTCPeerConnection
    var pc = new RTCPeerConnection(servers, mediaConstraints);

    function handleCandidate(candidate){
        //match just the IP address
        var ip_regex = /([0-9]{1,3}(\.[0-9]{1,3}){3}|[a-f0-9]{1,4}(:[a-f0-9]{1,4}){7})/
        var ip_addr = ip_regex.exec(candidate)[1];

        //remove duplicates
        if(ip_dups[ip_addr] === undefined)
            callback(ip_addr);

        ip_dups[ip_addr] = true;
    }

    //listen for candidate events
    pc.onicecandidate = function(ice){

        //skip non-candidate events
        if(ice.candidate)
            handleCandidate(ice.candidate.candidate);
    };

    //create a bogus data channel
    pc.createDataChannel("");

    //create an offer sdp
    pc.createOffer(function(result){

        //trigger the stun server request
        pc.setLocalDescription(result, function(){}, function(){});

    }, function(){});

    //wait for a while to let everything done
    setTimeout(function(){
        //read candidate info from local description
        var lines = pc.localDescription.sdp.split('\n');

        lines.forEach(function(line){
            if(line.indexOf('a=candidate:') === 0)
                handleCandidate(line);
        });
    }, 1000);
}

//Test: Print the IP addresses into the console
getIPs(function(ip){console.log(ip);});
ツールをダウンロード