
Demo: https://diafygi.github.io/webrtc-ips/
Демо: https://diafygi.github.io/webrtc-ips/
Firefox и Chrome реализовали WebRTC, который позволяет отправлять запросы к STUN-серверам, возвращающим локальный и публичный IP-адреса пользователя. Результаты этих запросов доступны из JavaScript, поэтому теперь вы можете получать локальный и публичный IP-адреса пользователя на JavaScript. Этот демонстрационный пример показывает реализацию этой возможности.
Кроме того, эти STUN-запросы выполняются вне обычного процесса XMLHttpRequest, поэтому они не видны в консоли разработчика и не могут быть заблокированы такими плагинами, как AdBlockPlus или Ghostery. Это делает такие запросы доступными для онлайн-отслеживания, если рекламодатель настроит STUN-сервер с wildcard-доменом.
Ниже приведена аннотированная демонстрационная функция, которая выполняет STUN-запрос. Вы можете скопировать и вставить её в консоль разработчика Firefox или Chrome, чтобы запустить тест.
//get the IP addresses associated with an account
function getIPs(callback){
var ip_dups = {};
//compatibility for firefox and chrome
var RTCPeerConnection = window.RTCPeerConnection
|| window.mozRTCPeerConnection
|| window.webkitRTCPeerConnection;
var useWebKit = !!window.webkitRTCPeerConnection;
//bypass naive webrtc blocking using an iframe
if(!RTCPeerConnection){
//NOTE: you need to have an iframe in the page right above the script tag
//
//
//<script>...getIPs called in here...
//
var win = iframe.contentWindow;
RTCPeerConnection = win.RTCPeerConnection
|| win.mozRTCPeerConnection
|| win.webkitRTCPeerConnection;
useWebKit = !!win.webkitRTCPeerConnection;
}
//minimal requirements for data connection
var mediaConstraints = {
optional: [{RtpDataChannels: true}]
};
var servers = {iceServers: [{urls: "stun:stun.services.mozilla.com"}]};
//construct a new RTCPeerConnection
var pc = new RTCPeerConnection(servers, mediaConstraints);
function handleCandidate(candidate){
//match just the IP address
var ip_regex = /([0-9]{1,3}(\.[0-9]{1,3}){3}|[a-f0-9]{1,4}(:[a-f0-9]{1,4}){7})/
var ip_addr = ip_regex.exec(candidate)[1];
//remove duplicates
if(ip_dups[ip_addr] === undefined)
callback(ip_addr);
ip_dups[ip_addr] = true;
}
//listen for candidate events
pc.onicecandidate = function(ice){
//skip non-candidate events
if(ice.candidate)
handleCandidate(ice.candidate.candidate);
};
//create a bogus data channel
pc.createDataChannel("");
//create an offer sdp
pc.createOffer(function(result){
//trigger the stun server request
pc.setLocalDescription(result, function(){}, function(){});
}, function(){});
//wait for a while to let everything done
setTimeout(function(){
//read candidate info from local description
var lines = pc.localDescription.sdp.split('\n');
lines.forEach(function(line){
if(line.indexOf('a=candidate:') === 0)
handleCandidate(line);
});
}, 1000);
}
//Test: Print the IP addresses into the console
getIPs(function(ip){console.log(ip);});