使用Python解密Chrome密码报AES密钥长度356字节错误如何解决
错误原因
你从Chrome Local State 文件中提取的 encrypted_key 是Base64编码的字符串,还包含固定前缀,并非原生可用的AES密钥。AES仅支持16/24/32字节长度的密钥(对应AES-128/AES-192/AES-256),直接传入原始字符串会触发长度错误。
修复步骤(Windows平台)
- 先安装必要依赖:
pip install pywin32 pycryptodome - 对原始密钥做解码、去前缀、DPAPI解密处理,同时补充GCM模式的tag校验逻辑,修复后的完整代码如下:
import base64 import win32crypt import sqlite3 from Cryptodome.Cipher import AES # 替换为你从Local State中复制的原始encrypted_key字符串 raw_secret_key = "<替换为你的原始密钥字符串>" # 密钥预处理流程 decoded_key = base64.b64decode(raw_secret_key) # 去掉解码后前5字节的固定"DPAPI"前缀 stripped_key = decoded_key[5:] # 调用Windows DPAPI接口解密得到真实AES密钥 secret_key = win32crypt.CryptUnprotectData(stripped_key, None, None, None, 0)[1] # 读取Login Data数据库逻辑 conn = sqlite3.connect("login.db") cursor = conn.cursor() cursor.execute("SELECT action_url, username_value, password_value FROM logins") for index,login in enumerate(cursor.fetchall()): url = login[0] username = login[1] ciphertext= login[2] # 跳过非Chrome v10版本加密的旧密码 if not ciphertext.startswith(b'v10'): continue print("Url:",url) print("Username:",username) # 提取IV、加密内容、GCM校验tag initialisation_vector = ciphertext[3:15] encrypted_password = ciphertext[15:-16] gcm_tag = ciphertext[-16:] # 解密 cipher = AES.new(secret_key, AES.MODE_GCM, initialisation_vector) decrypted_pass = cipher.decrypt_and_verify(encrypted_password, gcm_tag) decrypted_pass = decrypted_pass.decode() print("Decrypted Password:", decrypted_pass, "\n") conn.close()
其他平台注意事项
- MacOS平台:Chrome密钥存储在系统钥匙串中,需通过
security命令读取解密,无需DPAPI调用 - Linux平台:Chrome密钥用libsecret加密存储,需调用对应libsecret接口解密
内容的提问来源于stack exchange,提问作者Archangel
相关产品推荐
相关产品推荐

