mirror of
https://github.com/moonD4rk/HackBrowserData.git
synced 2026-05-19 18:58:03 +02:00
ad020cf135
* chore: downgrade golang version to 1.20, support windows 7 * chore: Update dependencies for Go project. - Update dependencies in go.sum - Improvements and optimizations in various files - Bug fixes and error handling enhancements * chore: Update modernc.org/sqlite library versions in go.mod and go.sum files - Update version of `modernc.org/sqlite` to `v1.31.1` in `go.mod` and `go.sum` files - Update module hash in `go.sum` file for `modernc.org/sqlite` - Ensure consistency between `go.mod` and `go.sum` files in relation to `modernc.org/sqlite` version * chore: replace log/slog with standard logger (#436) * chore: replace log/slog with standard logger * chore: Update Go dependencies and versions - Update Go version from `1.22.5` to `1.20` and other dependencies - Update critical dependencies to latest versions - Ensure compatibility with new versions of dependencies * chore: Optimize dependency management in workflows - Update build and lint workflows to use `go mod tidy` for getting dependencies - Change modules download mode to `'mod'` in linters configuration - Add step to get dependencies in lint workflow * refactor: Update dependencies and refactor Chromium key deletion logic - Update `modernc.org/sqlite` to `v1.31.1` in `go.mod` and `go.sum` - Increase version number to `0.5.0` in `cmd/hack-browser-data/main.go` - Refactor and update logic for filtering and copying items in `browser/chromium/chromium.go` * Improve logging functionality and data type conversion - Add `String()` method to `DataType` enum in types.go - Update log level to Debug in logger_test.go - Set log level to Debug in `TestLoggerDebug` and `TestLoggerDebugf` functions
163 lines
4.0 KiB
Go
163 lines
4.0 KiB
Go
package cookie
|
|
|
|
import (
|
|
"database/sql"
|
|
"os"
|
|
"sort"
|
|
"time"
|
|
|
|
// import sqlite3 driver
|
|
_ "modernc.org/sqlite"
|
|
|
|
"github.com/moond4rk/hackbrowserdata/crypto"
|
|
"github.com/moond4rk/hackbrowserdata/extractor"
|
|
"github.com/moond4rk/hackbrowserdata/log"
|
|
"github.com/moond4rk/hackbrowserdata/types"
|
|
"github.com/moond4rk/hackbrowserdata/utils/typeutil"
|
|
)
|
|
|
|
func init() {
|
|
extractor.RegisterExtractor(types.ChromiumCookie, func() extractor.Extractor {
|
|
return new(ChromiumCookie)
|
|
})
|
|
extractor.RegisterExtractor(types.FirefoxCookie, func() extractor.Extractor {
|
|
return new(FirefoxCookie)
|
|
})
|
|
}
|
|
|
|
type ChromiumCookie []cookie
|
|
|
|
type cookie struct {
|
|
Host string
|
|
Path string
|
|
KeyName string
|
|
encryptValue []byte
|
|
Value string
|
|
IsSecure bool
|
|
IsHTTPOnly bool
|
|
HasExpire bool
|
|
IsPersistent bool
|
|
CreateDate time.Time
|
|
ExpireDate time.Time
|
|
}
|
|
|
|
const (
|
|
queryChromiumCookie = `SELECT name, encrypted_value, host_key, path, creation_utc, expires_utc, is_secure, is_httponly, has_expires, is_persistent FROM cookies`
|
|
)
|
|
|
|
func (c *ChromiumCookie) Extract(masterKey []byte) error {
|
|
db, err := sql.Open("sqlite", types.ChromiumCookie.TempFilename())
|
|
if err != nil {
|
|
return err
|
|
}
|
|
defer os.Remove(types.ChromiumCookie.TempFilename())
|
|
defer db.Close()
|
|
rows, err := db.Query(queryChromiumCookie)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
defer rows.Close()
|
|
for rows.Next() {
|
|
var (
|
|
key, host, path string
|
|
isSecure, isHTTPOnly, hasExpire, isPersistent int
|
|
createDate, expireDate int64
|
|
value, encryptValue []byte
|
|
)
|
|
if err = rows.Scan(&key, &encryptValue, &host, &path, &createDate, &expireDate, &isSecure, &isHTTPOnly, &hasExpire, &isPersistent); err != nil {
|
|
log.Errorf("scan chromium cookie error: %v", err)
|
|
}
|
|
|
|
cookie := cookie{
|
|
KeyName: key,
|
|
Host: host,
|
|
Path: path,
|
|
encryptValue: encryptValue,
|
|
IsSecure: typeutil.IntToBool(isSecure),
|
|
IsHTTPOnly: typeutil.IntToBool(isHTTPOnly),
|
|
HasExpire: typeutil.IntToBool(hasExpire),
|
|
IsPersistent: typeutil.IntToBool(isPersistent),
|
|
CreateDate: typeutil.TimeEpoch(createDate),
|
|
ExpireDate: typeutil.TimeEpoch(expireDate),
|
|
}
|
|
if len(encryptValue) > 0 {
|
|
if len(masterKey) == 0 {
|
|
value, err = crypto.DecryptWithDPAPI(encryptValue)
|
|
} else {
|
|
value, err = crypto.DecryptWithChromium(masterKey, encryptValue)
|
|
}
|
|
if err != nil {
|
|
log.Errorf("decrypt chromium cookie error: %v", err)
|
|
}
|
|
}
|
|
cookie.Value = string(value)
|
|
*c = append(*c, cookie)
|
|
}
|
|
sort.Slice(*c, func(i, j int) bool {
|
|
return (*c)[i].CreateDate.After((*c)[j].CreateDate)
|
|
})
|
|
return nil
|
|
}
|
|
|
|
func (c *ChromiumCookie) Name() string {
|
|
return "cookie"
|
|
}
|
|
|
|
func (c *ChromiumCookie) Len() int {
|
|
return len(*c)
|
|
}
|
|
|
|
type FirefoxCookie []cookie
|
|
|
|
const (
|
|
queryFirefoxCookie = `SELECT name, value, host, path, creationTime, expiry, isSecure, isHttpOnly FROM moz_cookies`
|
|
)
|
|
|
|
func (f *FirefoxCookie) Extract(_ []byte) error {
|
|
db, err := sql.Open("sqlite", types.FirefoxCookie.TempFilename())
|
|
if err != nil {
|
|
return err
|
|
}
|
|
defer os.Remove(types.FirefoxCookie.TempFilename())
|
|
defer db.Close()
|
|
|
|
rows, err := db.Query(queryFirefoxCookie)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
defer rows.Close()
|
|
for rows.Next() {
|
|
var (
|
|
name, value, host, path string
|
|
isSecure, isHTTPOnly int
|
|
creationTime, expiry int64
|
|
)
|
|
if err = rows.Scan(&name, &value, &host, &path, &creationTime, &expiry, &isSecure, &isHTTPOnly); err != nil {
|
|
log.Errorf("scan firefox cookie error: %v", err)
|
|
}
|
|
*f = append(*f, cookie{
|
|
KeyName: name,
|
|
Host: host,
|
|
Path: path,
|
|
IsSecure: typeutil.IntToBool(isSecure),
|
|
IsHTTPOnly: typeutil.IntToBool(isHTTPOnly),
|
|
CreateDate: typeutil.TimeStamp(creationTime / 1000000),
|
|
ExpireDate: typeutil.TimeStamp(expiry),
|
|
Value: value,
|
|
})
|
|
}
|
|
|
|
sort.Slice(*f, func(i, j int) bool {
|
|
return (*f)[i].CreateDate.After((*f)[j].CreateDate)
|
|
})
|
|
return nil
|
|
}
|
|
|
|
func (f *FirefoxCookie) Name() string {
|
|
return "cookie"
|
|
}
|
|
|
|
func (f *FirefoxCookie) Len() int {
|
|
return len(*f)
|
|
}
|