如何在VB.NET中获取并解密PHP传递的加密Cookie?
现有代码示例
PHP调用端表单代码
<form name="WIP" method="post" action="https://somesite.space/defaulttest.aspx" id="new_user_session" target="_blank"> <input type="input" id="user_session_username_input" name="user_session[username]" value='<?php echo $_COOKIE["username"];?>' /> <input type="input" id="user_session_password_input" name="user_session[password]" value='<?php echo $_COOKIE["password"];?>' /> <button type="submit" name="callwip">hidden submit button</button> </form>
PHP请求头打印脚本
<?php function getRequestHeaders() { $headers = array(); foreach($_SERVER as $key => $value) { if (substr($key, 0, 5) <> 'HTTP_') { continue; } $header = str_replace(' ', '-', ucwords(str_replace('_', ' ', strtolower(substr($key, 5))))); $headers[$header] = $value; } return $headers; } $headers = getRequestHeaders(); foreach ($headers as $header => $value) { echo "$header: $value <br />"; echo htmlspecialchars($_COOKIE["name"]); } ?>
观测到的请求头Cookie内容
Cookie:ASPXANONYMOUS=zJOR0PPn1wEkAAAANTM4MjVmNTgtNjBmZi00OTE5LWJhMDctMzZhNDE2MzNiMjhmJMtw8PE9cOVf21RLcsEj_oGjnQk1
VB.NET测试代码
Imports System.Data Imports System.Data.SqlClient Imports DataHelper Partial Class _Default Inherits System.Web.UI.Page Protected Sub Page_Load(ByVal sender As Object, ByVal e As System.EventArgs) Handles Me.Load lblnameText.Text = Request.QueryString("id") lblpasswordText.Text = Request.QueryString("name") lblWelcomeText.Text = Request.AnonymousID End Sub End Class
问题核心
当前VB.NET代码无法获取PHP端提交的用户名密码信息,Request.QueryString返回空,Request.AnonymousID仅返回GUID格式的标识,和预期的加密Cookie内容不符,需要明确获取和解密目标数据的方法。
解决方案
- 纠正参数获取方式的错误
你当前使用Request.QueryString是获取GET请求URL参数的方法,但PHP端表单用的是method="post"提交,所以需要改用Request.Form获取POST表单字段,对应字段名要和PHP表单的name属性一致:
' 取表单提交的用户名密码 lblnameText.Text = Request.Form("user_session[username]") lblpasswordText.Text = Request.Form("user_session[password]")
- 明确Cookie的获取方式
Request.AnonymousID是ASP.NET框架自带的匿名用户标识,对应你观测到的ASPXANONYMOUSCookie,和PHP端存储的username、password自定义Cookie无关。要获取自定义Cookie需要通过Request.Cookies集合读取:
' 直接读取请求携带的Cookie(仅同域名/父域名下Cookie可正常携带) Dim usernameCookie As HttpCookie = Request.Cookies("username") Dim passwordCookie As HttpCookie = Request.Cookies("password") If usernameCookie IsNot Nothing Then lblnameText.Text = usernameCookie.Value End If If passwordCookie IsNot Nothing Then lblpasswordText.Text = passwordCookie.Value End If
如果PHP站点和VB.NET站点跨域,默认Cookie不会随请求携带,优先用表单POST的方式传递参数更稳妥。
3. 解密逻辑说明
如果你拿到的username、password的Cookie值是加密的,需要确认PHP端存储Cookie时使用的加密算法、密钥、偏移量(IV)等参数,两边使用相同的对称加密算法(如AES、DES)即可解密。如果是哈希加密(如MD5、bcrypt)属于不可逆加密,无法解密,只能用相同算法加密后做一致性校验。
内容的提问来源于stack exchange,提问作者Mark Clark
相关产品推荐
相关产品推荐

