如何解密/转换Plus500网页获取的黄金收盘价加密数据?
Alright, let's break down how to crack this encrypted data from Plus500. You tried Base64 and it didn't work—no surprise, because their front-end data isn't just plain Base64; it's almost certainly using a custom obfuscation scheme or light symmetric encryption. Since you know the gold closing price should land between 1292-1304, we can use that to guide our approach.
1. Steal the Decryption Logic Directly from Their Frontend (Most Reliable)
Plus500 has to decrypt this data in your browser to display it, so the code is already there. Here's how to grab it:
- Open plus500.com in Chrome/Firefox, hit F12 to open DevTools.
- Go to the Network tab, then trigger a stock quote load (search for gold, for example). Look for an XHR/fetch request that returns the encrypted JSON you're dealing with.
- Switch to the Sources tab and search for keywords related to decryption: try
decode,decrypt, or even fragments from your encrypted string likeLtorQs. - Once you find the decrypt function, you can either run it directly in the DevTools console with your encrypted data, or copy the function logic into Excel VBA, Python, or whatever tool you're using to process the data.
2. Reverse-Engineer Character Mappings Using Known Plaintext
Since you know the gold price is a 4-digit number (1292-1304), you can use this to guess how the encrypted string maps to numbers:
- Look at the structure of your encrypted data: there are repeated patterns like
Lt,Qs, and0Leverywhere. This suggests fixed-length character groups (2-4 chars) might map to individual digits or symbols. - Pick a segment of the encrypted string that you suspect corresponds to the gold price. Compare the frequency of character groups here to the frequency of digits in typical stock prices (e.g., 0, 1, 2 are common) to start building a mapping table.
3. Fix the Base64 Encoding and Try Again
Your encrypted string ends with ==, which is a Base64 padding character—but it's probably been modified with character substitutions. Try reversing those first:
- Base64 uses
A-Za-z0-9+/=as valid characters. Your string has lots of0L,Lt,Qs—these are likely replacements for/,+, or=. - Test substitution rules: for example, replace all
0Lwith/,Ltwith+,Qswith=, then run the modified string through a Base64 decoder. If that doesn't work, swap the substitutions (e.g.,Lt=/,Qs=+) and try again.
4. Test XOR Encryption
XOR is a super common lightweight encryption method for front-end data. Here's how to test it:
- Convert your encrypted string into an array of ASCII values.
- Pick a candidate key (try platform-related strings like "plus500", "gold", or even single bytes like
0x1For0x20). - XOR each character in your encrypted string with the corresponding character in the key (loop the key if it's shorter than the encrypted string).
- Convert the resulting values back to numbers or text—if you hit something in the 1292-1304 range, you've found the right key.
If none of these quick fixes work, go back to the first method—grabbing the actual decrypt logic from their frontend is guaranteed to work, since that's exactly what their site uses to show you the prices.
内容的提问来源于stack exchange,提问作者A_l_e_x

