如何使用Python读取并解密Chrome本地加密Cookie?
Absolutely you can decrypt those encrypted Chrome cookie values locally using Python! Let’s clear up one detail first: modern Chrome versions on Windows don’t use Triple DES—they rely on the Windows Data Protection API (DPAPI) to encrypt sensitive data like cookies. This ties encryption to your user account, so only your account can decrypt the values (a built-in security measure).
Here’s a step-by-step guide to make this work:
Prerequisites
- Make sure Chrome is closed before accessing the Cookies file—Chrome locks this database while running, preventing sqlite3 from connecting.
- You’ll need the
pywin32library for accessing DPAPI. Install it via pip:pip install pywin32 - This only works on Windows, since DPAPI is a Windows-exclusive feature.
Full Code Example
import sqlite3 import win32crypt def decrypt_chrome_cookie(encrypted_value): # Chrome adds a version prefix (usually b'v10' or b'v11') to encrypted data if encrypted_value.startswith((b'v10', b'v11')): encrypted_data = encrypted_value[3:] # Strip the prefix before decrypting else: encrypted_data = encrypted_value # Use DPAPI to decrypt the data tied to your user account try: # CryptUnprotectData returns a tuple; the second element is the decrypted bytes decrypted_bytes = win32crypt.CryptUnprotectData(encrypted_data, None, None, None, 0)[1] return decrypted_bytes.decode('utf-8') # Convert bytes to readable string except Exception as e: print(f"Decryption failed: {str(e)}") return None # Connect to Chrome's Cookies database db_path = r'C:\Users\usr\AppData\Local\Google\Chrome\User Data\Default\Cookies' conn = sqlite3.connect(db_path) cursor = conn.cursor() # Replace '<target-cookie-name>' with the actual name of the cookie you want cursor.execute("SELECT encrypted_value FROM cookies WHERE name = ?", ('<target-cookie-name>',)) result = cursor.fetchone() if result: encrypted_val = result[0] decrypted_value = decrypt_chrome_cookie(encrypted_val) if decrypted_value: print(f"Success! Decrypted cookie value: {decrypted_value}") else: print("Failed to decrypt the cookie.") else: print("Cookie not found in the database.") # Clean up the database connection conn.close()
Key Notes
- DPAPI Context: The decryption only works if you’re logged into the same Windows user account that Chrome uses. If you try to read cookies from another user’s profile, DPAPI will refuse to decrypt the data (this is intentional for security).
- Prefix Handling: Always check for the version prefix (
v10/v11)—skipping this step will cause decryption to fail. - Old Chrome Versions: If you’re dealing with a very old Chrome build that actually uses Triple DES, you’d need to extract the encryption key from Chrome’s local storage (which is now deprecated and much more complex). For 99% of use cases, DPAPI is the correct approach.
内容的提问来源于stack exchange,提问作者TheStrangeQuark
相关产品推荐
相关产品推荐

