Suppose you want to obfuscate an iframe with src=https://www.phpkobo.com/ 1) Fetch the content of https://www.phpkobo.com/ This is the hard part! You will get an error message like this --------------------------------------------- Access to fetch at 'https://www.phpkobo.com/' from origin 'http://php80ub20.solar.lan' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. If an opaque response serves your needs, set the request's mode to 'no-cors' to fetch the resource with CORS disabled. --------------------------------------------- * 'Access-Control-Allow-Origin'`を詳しく調べる必要がある。 * この問題を迂回したければ、JSに代わりに、PHPでFetchする。 2) Add to the webpage content in order to solve relative paths. 3) Create a blob of the content(https://www.phpkobo.com/) var blob = new Blob(['hey!'], {type : 'text/html'}); 4) Create URL with createObjectURL(blob) --------------------------------------------- var newurl = window.URL.createObjectURL(blob); --------------------------------------------- 5) Set the URL to an iframe --------------------------------------------- document.getElementById("myFrame").src = newurl; ---------------------------------------------