Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
ip-obfuscation — 使用 DWORD、八进制、十六进制、IPv6 映射和伪造域名 @ 技巧生成混淆的 IP 地址和 URL,用于渗透测试、钓鱼意识培训和 URL 过滤器测试。 | Kitploit
工具/GitHubGitHub/hackinglz/ip-obfuscation
冒充工具钓鱼攻击WAF绕过Web安全渗透测试社会工程学实用工具与框架学习与教育红队
GitHubhackinglz/ip-obfuscation

ip-obfuscation

使用 DWORD、八进制、十六进制、IPv6 映射和伪造域名 @ 技巧生成混淆的 IP 地址和 URL,用于渗透测试、钓鱼意识培训和 URL 过滤器测试。

445749个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库

IP 混淆器

一个用于生成混淆 IP 地址和 URL 的安全测试工具包。适用于渗透测试、安全研究、钓鱼意识培训以及测试 URL 解析器/过滤器。

概述

该工具包提供两种界面:

  • ip_obfuscator.html - 基于 Web 的图形界面,用于交互式使用
  • ip_obfuscator.py - 命令行工具,用于脚本编写和自动化

两种工具生成相同的混淆技术,包括:

  • DWORD/整数格式(十进制、十六进制、八进制)
  • 点分表示法变体(十六进制、八进制、混合进制)
  • IPv6 映射地址
  • URL 权威部分技巧(使用 @ 的伪造域名)
  • B/C 类简写表示法
  • 溢出技术
  • URL 编码变体

Web 界面(ip_obfuscator.html)

在任何现代浏览器中打开 ip_obfuscator.html。无需服务器。

功能

  • HTTPS 切换 - 在 HTTP 和 HTTPS 协议之间切换
  • 过滤/搜索 - 按关键字实时过滤结果
  • 导出 - 将结果下载为 JSON 或 CSV
  • 在浏览器中测试 - 在新标签页中打开任何生成的 URL
  • 可折叠分类 - 点击标题展开/折叠各部分
  • 安全区域分析 - 查看哪些格式会触发 Windows 本地 Intranet 区域

截图工作流程

  1. 输入目标 IP 地址(例如 192.168.1.100)
  2. 为 @ 技巧设置伪造域名(例如 secure.bank.com)
  3. 根据需要配置路径和端口
  4. 如需要则切换 HTTPS
  5. 点击“生成混淆”
  6. 使用标签页在 URL、IP 格式和安全区域之间切换
  7. 点击任意结果进行复制,或使用“在浏览器中测试”

命令行工具(ip_obfuscator.py)

环境要求

  • Python 3.6+
  • 无外部依赖(仅使用标准库)

基本用法

# Show all obfuscation formats for an IP
python3 ip_obfuscator.py 192.168.1.100

# Generate obfuscated URLs
python3 ip_obfuscator.py 192.168.1.100 --url

# With fake domain and path
python3 ip_obfuscator.py 192.168.1.100 --url --fake-domain secure.bank.com --path /login

命令行选项

选项短选项描述
--url-u生成完整 URL 而不仅仅是 IP 格式
--fake-domain-f用于 @ 技巧的伪造域名(默认:google.com)
--fake-pass-w用于 user:pass@host 格式的伪造密码
--path-pURL 路径(默认:/)
--port-P端口号
--https-s使用 HTTPS 而非 HTTP
--json-j以 JSON 格式输出
--filter-F按关键字过滤结果
--list-l紧凑列表输出(仅值)
--zones-z分析 Windows 安全区域影响
--decode-d将混淆的 IP 解码回标准形式

示例

使用伪造域名生成 URL

python3 ip_obfuscator.py 192.168.1.100 --url --fake-domain secure.bank.com --path /login

输出:

================================================================================
OBFUSCATED URL GENERATOR
================================================================================
  Target IP:     192.168.1.100
  Fake Domain:   secure.bank.com
  Fake Password: (none)
  Port:          (default)
  Path:          /login
  Protocol:      HTTP
================================================================================

DWORD/INTEGER FORMATS
--------------------------------------------------------------------------------

  Standard (no obfuscation):
  http://192.168.1.100/login

  Decimal DWORD:
  http://3232235876/login

  Hex DWORD:
  http://0xC0A80164/login

  Octal DWORD:
  http://030052000544/login

...

使用 JSON 输出过滤结果

python3 ip_obfuscator.py 192.168.1.100 --url --fake-domain secure.bank.com --filter "fake auth" --json

输出:

{
  "Fake Auth + Decimal DWORD": "http://secure.bank.com@3232235876/",
  "Fake Auth + Hex DWORD": "http://secure.bank.com@0xc0a80164/",
  "Fake Auth + Octal DWORD": "http://secure.bank.com@030052000544/",
  "Fake Auth + Dotted Hex": "http://[email protected]/",
  "Fake Auth + Dotted Octal": "http://[email protected]/",
  "Fake Auth + IPv6 Mapped (hex)": "http://secure.bank.com@[::ffff:c0a8:164]/",
  "Fake Auth + IPv6 Mapped (decimal)": "http://secure.bank.com@[::ffff:192.168.1.100]/",
  "Fake Auth + IPv6 Mapped (full)": "http://secure.bank.com@[0000:0000:0000:0000:0000:ffff:c0a8:0164]/",
  "Fake Auth + Class B": "http://[email protected]/",
  "Fake Auth + Class C": "http://[email protected]/"
}

生成 HTTPS URL

python3 ip_obfuscator.py 192.168.1.100 --url --https --filter ipv6

仅列出 IPv6 格式

python3 ip_obfuscator.py 192.168.1.100 --list --filter ipv6

输出:

All obfuscated forms of 192.168.1.100:

  ::ffff:192.168.1.100
  ::ffff:c0a8:164
  0000:0000:0000:0000:0000:ffff:c0a8:0164
  0:0:0:0:0:ffff:c0a8:164
  ::ffff:c0a80164
  ::192.168.1.100
  ::c0a8:164
  [::ffff:c0a8:164]
  [::ffff:192.168.1.100]
  [0000:0000:0000:0000:0000:ffff:c0a8:0164]

解码混淆的 URL

python3 ip_obfuscator.py --decode "http://secure.bank.com@3232235876/login"

输出:

Input:   http://secure.bank.com@3232235876/login
Decoded: 192.168.1.100

安全区域分析

python3 ip_obfuscator.py 192.168.1.100 --zones

输出:

================================================================================
MICROSOFT SECURITY ZONES ANALYSIS
================================================================================

The 'Dot Rule' (PlainHostName rule):
  • Hostname WITHOUT dots → Local Intranet Zone
  • Hostname WITH dots    → Internet Zone

⚠️  SECURITY IMPACT of Intranet Zone:
  • Automatic NTLM/Kerberos credential release (credential theft!)
  • Less restrictive ActiveX/script policies
  • May bypass security prompts and Mark-of-the-Web

================================================================================
Target IP: 192.168.1.100
================================================================================

🔴 DOTLESS → LOCAL INTRANET ZONE (HIGH RISK - credential leak)
--------------------------------------------------------------------------------
  Decimal DWORD
    URL: http://3232235876/
    Note: CONFIRMED: MS98-016 specifically documents this as Intranet Zone bypass

  Hex DWORD (0x prefix)
    URL: http://0xC0A80164/
    Note: CONFIRMED: Numeric hostname without dots → Intranet Zone

  Octal DWORD
    URL: http://030052000544/
    Note: Octal integer without dots → Intranet Zone

🟢 DOTTED → INTERNET ZONE (normal security)
--------------------------------------------------------------------------------
  Standard Dotted Decimal
    URL: http://192.168.1.100/

  Dotted Hex
    URL: http://0xC0.0xA8.0x1.0x64/
...

混淆技术参考

分类示例描述
十进制 DWORD323223587632 位整数表示
十六进制 DWORD0xC0A80164十六进制整数
八进制 DWORD030052000544八进制整数(前导零)
点分十六进制0xC0.0xA8.0x1.0x64每个八位组以十六进制表示
点分八进制0300.0250.01.0144每个八位组以八进制表示
混合进制192.0xa8.01.100十进制/十六进制/八进制组合
B 类192.11010404第一个八位组 + 24 位值
C 类192.168.356两个八位组 + 16 位值
IPv6 映射::ffff:c0a8:164IPv4 映射的 IPv6 地址
伪造认证secure.bank.com@IPURL 权威部分技巧
溢出7527203172值 + 2^32(回绕)

安全注意事项

此工具适用于:

  • 渗透测试(经授权)
  • 安全研究
  • 钓鱼意识培训
  • 测试 URL 过滤器和解析器
  • CTF 挑战

请勿用于恶意目的。

参考资料

  • MS98-016:Internet Explorer URL 解析漏洞
  • SANS ISC Diary 关于 IP 混淆
  • Mandiant:URL Schema 混淆技术
  • inet_aton() 手册页(BSD sockets)

许可证

MIT 许可证 - 请负责任地使用。

下载工具