
DWORD、8進数、16進数、IPv6マップ、および偽ドメイン@トリックを使用して難読化されたIPアドレスとURLを生成し、ペネトレーションテスト、フィッシング意識向上、URLフィルターテストに使用します。
難読化された IP アドレスと URL を生成するためのセキュリティテストツールキット。ペネトレーションテスト、セキュリティリサーチ、フィッシング啓発トレーニング、URL パーサー/フィルターのテストに役立ちます。
このツールキットは 2 つのインターフェースを提供します:
ip_obfuscator.html - 対話的な使用のための Web ベース GUIip_obfuscator.py - スクリプトと自動化のためのコマンドラインツールどちらのツールも同じ難読化テクニックを生成します。これには以下が含まれます:
@ を使った偽ドメイン)ip_obfuscator.html)任意のモダンブラウザで ip_obfuscator.html を開きます。サーバーは不要です。
192.168.1.100)@ トリック用の偽ドメインを設定 (例: secure.bank.com)ip_obfuscator.py)# Show all obfuscation formats for an IP
python3 ip_obfuscator.py 192.168.1.100
# Generate obfuscated URLs
python3 ip_obfuscator.py 192.168.1.100 --url
# With fake domain and path
python3 ip_obfuscator.py 192.168.1.100 --url --fake-domain secure.bank.com --path /login
| Option | Short | Description |
|---|---|---|
--url | -u | IP 形式だけでなく完全な URL を生成 |
--fake-domain | -f | @ トリック用の偽ドメイン (デフォルト: google.com) |
--fake-pass | -w | user:pass@host 形式用の偽パスワード |
--path | -p | URL パス (デフォルト: /) |
--port | -P | ポート番号 |
--https | -s | HTTP の代わりに HTTPS を使用 |
--json | -j | JSON として出力 |
--filter | -F | キーワードで結果をフィルタリング |
--list | -l | コンパクトなリスト出力 (値のみ) |
--zones | -z | Windows セキュリティゾーンの影響を分析 |
--decode | -d | 難読化された IP を標準形式にデコード |
python3 ip_obfuscator.py 192.168.1.100 --url --fake-domain secure.bank.com --path /login
出力:
================================================================================
OBFUSCATED URL GENERATOR
================================================================================
Target IP: 192.168.1.100
Fake Domain: secure.bank.com
Fake Password: (none)
Port: (default)
Path: /login
Protocol: HTTP
================================================================================
DWORD/INTEGER FORMATS
--------------------------------------------------------------------------------
Standard (no obfuscation):
http://192.168.1.100/login
Decimal DWORD:
http://3232235876/login
Hex DWORD:
http://0xC0A80164/login
Octal DWORD:
http://030052000544/login
...
python3 ip_obfuscator.py 192.168.1.100 --url --fake-domain secure.bank.com --filter "fake auth" --json
出力:
{
"Fake Auth + Decimal DWORD": "http://secure.bank.com@3232235876/",
"Fake Auth + Hex DWORD": "http://secure.bank.com@0xc0a80164/",
"Fake Auth + Octal DWORD": "http://secure.bank.com@030052000544/",
"Fake Auth + Dotted Hex": "http://[email protected]/",
"Fake Auth + Dotted Octal": "http://[email protected]/",
"Fake Auth + IPv6 Mapped (hex)": "http://secure.bank.com@[::ffff:c0a8:164]/",
"Fake Auth + IPv6 Mapped (decimal)": "http://secure.bank.com@[::ffff:192.168.1.100]/",
"Fake Auth + IPv6 Mapped (full)": "http://secure.bank.com@[0000:0000:0000:0000:0000:ffff:c0a8:0164]/",
"Fake Auth + Class B": "http://[email protected]/",
"Fake Auth + Class C": "http://[email protected]/"
}
python3 ip_obfuscator.py 192.168.1.100 --url --https --filter ipv6
python3 ip_obfuscator.py 192.168.1.100 --list --filter ipv6
出力:
All obfuscated forms of 192.168.1.100:
::ffff:192.168.1.100
::ffff:c0a8:164
0000:0000:0000:0000:0000:ffff:c0a8:0164
0:0:0:0:0:ffff:c0a8:164
::ffff:c0a80164
::192.168.1.100
::c0a8:164
[::ffff:c0a8:164]
[::ffff:192.168.1.100]
[0000:0000:0000:0000:0000:ffff:c0a8:0164]
python3 ip_obfuscator.py --decode "http://secure.bank.com@3232235876/login"
出力:
Input: http://secure.bank.com@3232235876/login
Decoded: 192.168.1.100
python3 ip_obfuscator.py 192.168.1.100 --zones
出力:
================================================================================
MICROSOFT SECURITY ZONES ANALYSIS
================================================================================
The 'Dot Rule' (PlainHostName rule):
• Hostname WITHOUT dots → Local Intranet Zone
• Hostname WITH dots → Internet Zone
⚠️ SECURITY IMPACT of Intranet Zone:
• Automatic NTLM/Kerberos credential release (credential theft!)
• Less restrictive ActiveX/script policies
• May bypass security prompts and Mark-of-the-Web
================================================================================
Target IP: 192.168.1.100
================================================================================
🔴 DOTLESS → LOCAL INTRANET ZONE (HIGH RISK - credential leak)
--------------------------------------------------------------------------------
Decimal DWORD
URL: http://3232235876/
Note: CONFIRMED: MS98-016 specifically documents this as Intranet Zone bypass
Hex DWORD (0x prefix)
URL: http://0xC0A80164/
Note: CONFIRMED: Numeric hostname without dots → Intranet Zone
Octal DWORD
URL: http://030052000544/
Note: Octal integer without dots → Intranet Zone
🟢 DOTTED → INTERNET ZONE (normal security)
--------------------------------------------------------------------------------
Standard Dotted Decimal
URL: http://192.168.1.100/
Dotted Hex
URL: http://0xC0.0xA8.0x1.0x64/
...
| Category | Example | Description |
|---|---|---|
| Decimal DWORD | 3232235876 | 32 ビット整数表現 |
| Hex DWORD | 0xC0A80164 | 16 進整数 |
| Octal DWORD | 030052000544 | 8 進整数 (先頭ゼロ) |
| Dotted Hex | 0xC0.0xA8.0x1.0x64 | 各オクテットを 16 進数で |
| Dotted Octal | 0300.0250.01.0144 | 各オクテットを 8 進数で |
| Mixed Bases | 192.0xa8.01.100 | 10 進/16 進/8 進の組み合わせ |
| Class B | 192.11010404 | 最初のオクテット + 24 ビット値 |
| Class C | 192.168.356 | 2 オクテット + 16 ビット値 |
| IPv6 Mapped | ::ffff:c0a8:164 | IPv4 マップ IPv6 アドレス |
| Fake Auth | secure.bank.com@IP | URL オーソリティセクションのトリック |
| Overflow | 7527203172 | 値 + 2^32 (ラップアラウンド) |
このツールは以下を目的としています:
悪意のある目的には使用しないでください。
MIT License - 責任を持って使用してください。