已知明文密码与哈希值,如何获取Evo CMS的Blowfish加密密钥?
Great question—let’s work through this since you already have plaintext/hash pairs and a solid hunch about Blowfish. Here’s what you need to know:
First: Confirm It’s Blowfish (Bcrypt)
Blowfish-based password hashing (most commonly bcrypt) has a distinctive format. Check your existing hashes—they should start with a prefix like $2a$, $2b$, or $2y$ followed by a cost factor, a salt, and the hash itself (e.g., $2y$10$92IXUNpkjO0rOQ5byMi.Ye4oKoEa3Ro9llC/.og/at2.uheWG/igi). If your hashes match this pattern, you’re dealing with standard bcrypt.
Key Point: Bcrypt Doesn’t Require a Separate Encryption Key
Unlike some other hashing systems, bcrypt embeds the salt and algorithm parameters directly into the hash string. That means you don’t need to hunt down a secret key from Evo’s source code—all the info needed to verify a password is already in the hash itself.
How to Verify Passwords in Your Custom Backend
For PHP (Evo’s core language)
Use PHP’s built-in password_verify() function—it’s purpose-built for bcrypt and handles all the heavy lifting:
$plaintextPassword = "your-known-plaintext"; $storedHash = "the-corresponding-hash-from-evo-db"; if (password_verify($plaintextPassword, $storedHash)) { // Password is valid—allow login } else { // Invalid password }
You can also test if Evo uses the standard crypt() function under the hood (which is what password_verify() wraps) by running crypt($plaintextPassword, $storedHash) and comparing the result to the stored hash. If they match, you’re good to go.
For Other Languages
If your custom backend uses Python, Node.js, etc., use a bcrypt library compatible with your language:
- Python: Use the
bcryptpackage:import bcrypt plaintext = b"your-known-plaintext" stored_hash = b"the-corresponding-hash-from-evo-db" if bcrypt.checkpw(plaintext, stored_hash): print("Password matches!") - Node.js: Use the
bcryptnpm package:const bcrypt = require('bcrypt'); const plaintextPassword = "your-known-plaintext"; const storedHash = "the-corresponding-hash-from-evo-db"; bcrypt.compare(plaintextPassword, storedHash, (err, result) => { if (result) { // Valid password } });
If It’s Not Standard Bcrypt (Unlikely, But Possible)
If the hashes don’t match the bcrypt format, you can use your known plaintext/hash pair to reverse-engineer Evo’s custom logic:
- Search Evo’s source code for files handling user authentication—look for
login.processor.phpin themanager/processorsdirectory, or themodUserclass methods related to password validation. - Test variations of Blowfish hashing (different cost factors, salt handling) with your plaintext to see if you can replicate the stored hash.
Final Note
Since Evo is a fork of MODX Evolution, it’s highly likely it uses standard bcrypt for password hashing. Your known plaintext/hash pair is the perfect way to confirm—just run the verification code above, and if it returns true, you’re ready to implement this logic in your custom backend.
内容的提问来源于stack exchange,提问作者lpetrucci

