Show HN: Get your local and public IP addresses in JavaScript
github.com
github.com
If their request IP doesn't match up with this IP, there's a very high chance that the order will is fraudulent.
;)
> i think only amateurs would be so foolish
When I think of people using stolen credit cards to buy goods, I'm not envisaging a `leet hacking squad... That there are highly sophisticated cyber criminals in no way implies that all - or even most - are.HTTP proxy is not a SOCKS4 is not a SOCKS5. :)
What they'll do is buy from a proxy shop " " - usually someone(s) with a botnet and a lot of clients on that botnet - so the IPs are residentials. vip72.com is a popular one. They do provide a client which will allow you to tunnel your entire system through the proxy, but it's not required for use (and some people are wary of it)
Another useful heuristic is to check if the client is coming in from a public Tor exit. YMMV depending on the nature of goods being sold, but in our case not a single legit purchase came in this way and nearly all fraudulent purchases were through Tor.
The problem with disabling all these features on a case by case basis is that you contribute to a richer fingerprint this way. Browsers will become increasingly more vulnerable to fingerprinting and there doesn't seem to be a way to stop it without going back to the dark ages of the web.
To make it secure, disable all plugins.
To make it more private, that's another story. Poor Firefox actually tries its best not to make you identifiable in some superficial ways - e.g. lying about user agent in "obscure" OSes. My FF reports 'Mozilla/5.0 (Windows NT 6.1; WOW64; rv:15.0) Gecko/blah Firefox/blah', and I am not on Windows. I don't remember enabling anything like this in any way so I assume it is the default behaviour. This is with "nothing" as an option for DNT btw (neither yes nor no).
Ultimately this is moot as you can't get around your font & rendering fingerprints that can be extracted from a hidden canvas element, but hey. Still better than serving it up in a platter.
> your local IP is actually going to be very unique for some people, more so than just having this "feature" disabled.
How so? It'll fall ion pretty standard ranges. I only find any use/value in it when combined with the remote IP + the rest of your env. characteristics.
When you have to delve into about:config to disable it, 99.99% of people will have it enabled. This + your remote IP would pretty much identify you just fine.
${witty_double-edged_sword_quote}
This has some work to be done still, but it's a start in regard to blocking hidden canvas elements: https://addons.mozilla.org/en-US/firefox/addon/canvasblocker
https://www.torproject.org/projects/torbrowser/design/#Imple...
I'm willing to bet that almost everyone who has a single "home router"/NAT is going to be 192.168.1.2 or 192.168.1.3. There will be the exceptions on 10/8 or 173.16/12 but the majority of home networks will be 192.168/16.
I wish Chrome would provide this setting too.
One could do the same in Qubes, more elegantly. And indeed, I got the idea of workspace and gateway VMs from Joanna Rutkowska's early posts about the Qubes project.
I use various nested VPN chains, with three VPNs minimum. I also use a bunch of Whonix instances, connecting via VPN chains. And sometimes I play with JonDonym.
I can see limited circumstances where VPN/proxy->Tor, Tor->VPN/proxy, and VPN/proxy->Tor->VPN/proxy make sense, but no need for anything more complex than that.
That probably means I share the same fingerprint as everyone else using the same browser with JS disabled.
That's not a lot of people who have JS disabled.
The new trend is not only needed javascript but localstorage.
I cannot believe the sheer number of sites I have to use now that will not function without localstorage enabled.
I've tried disabling JS and all sites were completely broken and resulted in a horrible experience. I guess though if you set your bar very low few sites really need it.
Edit: owfffjaqvllmh4zi.onion reveals true IP addresses when using Chrome through Privoxy and Tor chain.
So the extra effort to get around adblockers?
Edit: I realized I didn't take this to its full conclusion. Guess the router's IP, exploit XSS to open ports on the router to your machine (JS knows your local IP already), carry on escalating from there.
Maybe those aren't common, but it's very common to have something that looks just like one (speaks HTTP on port 80), which is called a web server. That might be embedded in your router or other device, or it may be a configuration interface for your POS, or it might be hiding in some other dark and unpatched corner that was formerly hidden behind a firewall. Of course it would be nice if the server simply doesn't respond (while writing alarms to the log) when it sees an Upgrade: websocket header, but can we be sure that all our hidden servers are so well-behaved?
As for non-meaningful responses, isn't this equivalent to using <img src="http://192.168.1.1/admin?action=evil"> to send an HTTP request? That's also not restricted by same-origin, and never has been and never will be. You get the same result -- you cause an HTTP request to be sent somewhere, and the response isn't useful to you nor is the contents of the response visible to you, but the request and its side effects still happen.
I'm not super well-versed in websocket design, so I'm happy to be convinced I'm wrong, but that's my understanding of why it works the way it does.
It turns out that this script must employ this techinque. After inspecting the requests in chrome Dev tools it appears all my private ips were being collected and sent over the wire back to Braintree (or whatever company is hosting their fraud detection).
media.peerconnection.enabled is set to true
EDIT: hbbio's jsfiddle works
According to the docs, the error callback is not optional.
Edit: Apparently it is by design; ICMP ECHOs are blocked by default on AWS instances, on which stun.services.mozilla.com [54.172.47.69] is running. http://aws.amazon.com/articles/1145?_encoding=UTF8&jiveRedir...
1. Are you currently using WebRTC in any projects?
2. Are you planning on using WebRTC in the future?
3. Do you think that WebRTC should be enabled by default in browsers?
2. Obviously,
3. With explicit permit from user each time it's needed (like it's for webcam);
This site makes use of a SHA-1 Certificate; it's recommended you use certificates with signature algorithms that use hash functions stronger than SHA-1.[Learn More] webrtc-ips
TypeError: Not enough arguments to mozRTCPeerConnection.setLocalDescription.
Here's me hoping they're addressing these concerns already.The new bit is that you can now get local IPs. But that doesn't help someone trying to figure out if you're using a VPN.
The demo shows both my USA VPN IP address and my China Telecom IP address under "public addresses" (I strongly doubt this was possible before WebRTC). This means that Hulu, YouTube, Netflix etc. can now start blocking me even when I'm behind a VPN.
curl ifconfig.meHowever, like you pointed out, there are other ways than XHR to leak data if JS is enabled.
If JS is not enabled, the kinds of data that can be leaked is fewer (perhaps screen resolution and size).
Would welcome expert comments on our issue tracker: https://github.com/UprootLabs/gngr/issues/90
https://github.com/diafygi/webrtc-ips/blob/master/index.html...