
DWORD, 8진수, 16진수, IPv6 매핑, 가짜 도메인 @ 트릭을 사용하여 난독화된 IP 주소와 URL을 생성합니다. 침투 테스트, 피싱 인식 교육, URL 필터 테스트에 활용됩니다.
난독화된 IP 주소와 URL을 생성하기 위한 보안 테스트 툴킷입니다. 침투 테스트, 보안 연구, 피싱 인식 교육, URL 파서/필터 테스트에 유용합니다.
이 툴킷은 두 가지 인터페이스를 제공합니다:
ip_obfuscator.html - 대화형 사용을 위한 웹 기반 GUIip_obfuscator.py - 스크립팅 및 자동화를 위한 명령줄 도구두 도구 모두 동일한 난독화 기법을 생성하며, 다음을 포함합니다:
@를 사용한 가짜 도메인)ip_obfuscator.html)최신 브라우저에서 ip_obfuscator.html을 엽니다. 서버가 필요하지 않습니다.
192.168.1.100)@ 트릭을 위한 가짜 도메인 설정 (예: secure.bank.com)ip_obfuscator.py)# Show all obfuscation formats for an IP
python3 ip_obfuscator.py 192.168.1.100
# Generate obfuscated URLs
python3 ip_obfuscator.py 192.168.1.100 --url
# With fake domain and path
python3 ip_obfuscator.py 192.168.1.100 --url --fake-domain secure.bank.com --path /login
| Option | Short | Description |
|---|---|---|
--url | -u | IP 형식만이 아닌 전체 URL 생성 |
--fake-domain | -f | @ 트릭을 위한 가짜 도메인 (기본값: google.com) |
--fake-pass | -w | user:pass@host 형식을 위한 가짜 비밀번호 |
--path | -p | URL 경로 (기본값: /) |
--port | -P | 포트 번호 |
--https | -s | HTTP 대신 HTTPS 사용 |
--json | -j | JSON으로 출력 |
--filter | -F | 키워드로 결과 필터링 |
--list | -l | 간결한 목록 출력 (값만) |
--zones | -z | Windows 보안 영역 영향 분석 |
--decode | -d | 난독화된 IP를 표준 형식으로 디코딩 |
python3 ip_obfuscator.py 192.168.1.100 --url --fake-domain secure.bank.com --path /login
출력:
================================================================================
OBFUSCATED URL GENERATOR
================================================================================
Target IP: 192.168.1.100
Fake Domain: secure.bank.com
Fake Password: (none)
Port: (default)
Path: /login
Protocol: HTTP
================================================================================
DWORD/INTEGER FORMATS
--------------------------------------------------------------------------------
Standard (no obfuscation):
http://192.168.1.100/login
Decimal DWORD:
http://3232235876/login
Hex DWORD:
http://0xC0A80164/login
Octal DWORD:
http://030052000544/login
...
python3 ip_obfuscator.py 192.168.1.100 --url --fake-domain secure.bank.com --filter "fake auth" --json
출력:
{
"Fake Auth + Decimal DWORD": "http://secure.bank.com@3232235876/",
"Fake Auth + Hex DWORD": "http://secure.bank.com@0xc0a80164/",
"Fake Auth + Octal DWORD": "http://secure.bank.com@030052000544/",
"Fake Auth + Dotted Hex": "http://[email protected]/",
"Fake Auth + Dotted Octal": "http://[email protected]/",
"Fake Auth + IPv6 Mapped (hex)": "http://secure.bank.com@[::ffff:c0a8:164]/",
"Fake Auth + IPv6 Mapped (decimal)": "http://secure.bank.com@[::ffff:192.168.1.100]/",
"Fake Auth + IPv6 Mapped (full)": "http://secure.bank.com@[0000:0000:0000:0000:0000:ffff:c0a8:0164]/",
"Fake Auth + Class B": "http://[email protected]/",
"Fake Auth + Class C": "http://[email protected]/"
}
python3 ip_obfuscator.py 192.168.1.100 --url --https --filter ipv6
python3 ip_obfuscator.py 192.168.1.100 --list --filter ipv6
출력:
All obfuscated forms of 192.168.1.100:
::ffff:192.168.1.100
::ffff:c0a8:164
0000:0000:0000:0000:0000:ffff:c0a8:0164
0:0:0:0:0:ffff:c0a8:164
::ffff:c0a80164
::192.168.1.100
::c0a8:164
[::ffff:c0a8:164]
[::ffff:192.168.1.100]
[0000:0000:0000:0000:0000:ffff:c0a8:0164]
python3 ip_obfuscator.py --decode "http://secure.bank.com@3232235876/login"
출력:
Input: http://secure.bank.com@3232235876/login
Decoded: 192.168.1.100
python3 ip_obfuscator.py 192.168.1.100 --zones
출력:
================================================================================
MICROSOFT SECURITY ZONES ANALYSIS
================================================================================
The 'Dot Rule' (PlainHostName rule):
• Hostname WITHOUT dots → Local Intranet Zone
• Hostname WITH dots → Internet Zone
⚠️ SECURITY IMPACT of Intranet Zone:
• Automatic NTLM/Kerberos credential release (credential theft!)
• Less restrictive ActiveX/script policies
• May bypass security prompts and Mark-of-the-Web
================================================================================
Target IP: 192.168.1.100
================================================================================
🔴 DOTLESS → LOCAL INTRANET ZONE (HIGH RISK - credential leak)
--------------------------------------------------------------------------------
Decimal DWORD
URL: http://3232235876/
Note: CONFIRMED: MS98-016 specifically documents this as Intranet Zone bypass
Hex DWORD (0x prefix)
URL: http://0xC0A80164/
Note: CONFIRMED: Numeric hostname without dots → Intranet Zone
Octal DWORD
URL: http://030052000544/
Note: Octal integer without dots → Intranet Zone
🟢 DOTTED → INTERNET ZONE (normal security)
--------------------------------------------------------------------------------
Standard Dotted Decimal
URL: http://192.168.1.100/
Dotted Hex
URL: http://0xC0.0xA8.0x1.0x64/
...
| Category | Example | Description |
|---|---|---|
| Decimal DWORD | 3232235876 | 32비트 정수 표현 |
| Hex DWORD | 0xC0A80164 | 16진수 정수 |
| Octal DWORD | 030052000544 | 8진수 정수 (선행 0) |
| Dotted Hex | 0xC0.0xA8.0x1.0x64 | 각 옥텟을 16진수로 |
| Dotted Octal | 0300.0250.01.0144 | 각 옥텟을 8진수로 |
| Mixed Bases | 192.0xa8.01.100 | 10진수/16진수/8진수 조합 |
| Class B | 192.11010404 | 첫 번째 옥텟 + 24비트 값 |
| Class C | 192.168.356 | 두 옥텟 + 16비트 값 |
| IPv6 Mapped | ::ffff:c0a8:164 | IPv4 매핑 IPv6 주소 |
| Fake Auth | secure.bank.com@IP | URL authority 섹션 트릭 |
| Overflow | 7527203172 | 값 + 2^32 (래핑 어라운드) |
이 도구는 다음 용도로 사용됩니다:
악의적인 목적으로 사용하지 마십시오.
MIT License - 책임감 있게 사용하십시오.