> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/zh/web/business-logic/bypassing-authentication-via-encryption-oracle.md).

# 通过加密 Oracle 绕过认证

### 通过加密 Oracle 绕过身份验证

**实验说明**

这个实验存在一个逻辑缺陷，暴露了一个\*\*服务器端加密\*\* Oracle。通过利用这一弱点，可以伪造一个有效的加密值，从而绕过身份验证，访问管理员面板并删除用户 **carlos**.

提供的标识符：

* 用户： `wiener`
* 密码： `peter`

**初步观察**

在登录页面上， **保持登录状态** 选项可用。

<figure><img src="/files/d9825585afaa6dd4a27e4b2dc85ebd6aa6a3bd69" alt=""><figcaption></figcaption></figure>

使用时，会生成一个以 **Base64** 加密的 cookie，并存储在客户端。

<figure><img src="/files/d8d08e441cdab0323a2ce51cb7ae481d378143f5" alt=""><figcaption></figcaption></figure>

```bash
echo '0HE6oMYJL//S1fLwttqR7WMF3EX4KJmvfFRI53qpVnk=' | base64 -d

# 解码后的值是二进制密文，不是可读文本。
```

### 加密 Oracle 的识别

当提交有效评论时，没有观察到任何特定响应。

<figure><img src="/files/b88611cd2e49b8d2bd9dff65a8837881fcf80595" alt=""><figcaption></figcaption></figure>

但是，如果某条评论导致应用程序错误（例如无效的电子邮件地址），服务器会：

* 返回屏幕上显示的错误消息；

{% code overflow="wrap" %}

```bash
csrf=cFMQUjAyzETtEr8TLsoir7V5p4C3m4ZG&postId=4&comment=test&name=test&email=test&website=https://localhost
```

{% endcode %}

* 生成一个新的 cookie `通知`\*\*，已加密。

显示的内容例如：

<figure><img src="/files/948421421581472867191d8f4f40099b6362c163" alt=""><figcaption></figcaption></figure>

这表明：

* 服务器\*\*解密 cookie 的内容 `通知` ；

<figure><img src="/files/aba5664605e2e3ca382c1fa9b65aaacfb726eabe" alt=""><figcaption></figcaption></figure>

因此，服务器充当了 **加密与解密 Oracle**.

* 解密后的文本是 **重新注入到 HTML 响应中**.

<figure><img src="/files/25ca776752b1e8533d2e84557aa4980f8884233f" alt=""><figcaption></figcaption></figure>

### 与 Cookie 的关联

通过注入 cookie 的加密值\*\*

观察到的格式是：

<figure><img src="/files/87b9439c76674b8bbfe468c337e377d7a440b0cf" alt=""><figcaption></figcaption></figure>

这明显对应于：

* 一个用户名；
* 一个时间戳。

#### 伪造管理员身份

目标是让服务器加密以下字符串：

```bash
administrator:1766913113564
```

<figure><img src="/files/fde782e3ecee06aac8ef7f8f157f52672c1ba6e2" alt=""><figcaption></figcaption></figure>

为此，将该值注入脆弱字段（无效评论/电子邮件）中，从而导致：

* 显示包含该字符串的错误消息；

<figure><img src="/files/b8be4019bdd0c486c6d147f1fccfc766e7cd7adb" alt=""><figcaption></figcaption></figure>

生成一个新的 `通知` cookie，其中包含注入的文本。

{% code overflow="wrap" %}

```bash
Set-Cookie: notification=VQbs3ex4CbvKjTm0LM5wuZa79pnAzKI9MEsa1O0MbX%2fJpfl9baj6yL3ryxh4u6nyiWHVwxP7%2fVDPyft%2f1qAbbQ%3d%3d; HttpOnly
```

{% endcode %}

### 加密算法识别

通过任意截断加密值，服务器返回以下错误

```bash
PTBLGtTtDG1/yaX5fW2o%2bsi968sYeLup8olh1cMT%2b/1Qz8n7f9agG20%3d
```

`使用填充密码进行解密时，输入长度必须是 16 的倍数`

<figure><img src="/files/4d056e6b76f07d31662c7b9cda2b314f4eee72a8" alt=""><figcaption></figcaption></figure>

这清楚地表明在 **带填充的 AES**，以 **16 字节**.

<figure><img src="/files/882a50f820b664588f842108722403f1a223cc44" alt=""><figcaption></figcaption></figure>

#### 密文块操作

遇到的问题是消息末尾存在无效的填充字符。/ 为了解决这个问题，在注入链前先填充字符以正确对齐分组：

```
xxxxxxxxxadministrator:1766913113564
```

<figure><img src="/files/14c441c1ea2baa4a11a57cd7ced6d2531cb27bbc" alt=""><figcaption></figcaption></figure>

然后会生成一个新的加密 cookie。

VQbs3ex4CbvKjTm0LM5wuZJqwlVboMZ2IzNuiTfVH6iHj9RZUT59d5kGoS64tVE5wWiEfmp6VbJG%2bb%2fNW5%2bblA%3d%3d

### 裁剪并重组 Cookie

通过删除前两个 **加密块** （对应于填充），只保留包含：

<figure><img src="/files/7dc6fff2fc0993bf2ec856ae55f60ea6d9c04742" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/ca10d63352fcb9d4f1d88c5093cb861ef3c9f66b" alt=""><figcaption></figcaption></figure>

这个最终的加密值被服务器接受。

```
h4/UWVE%2bfXeZBqEuuLVROcFohH5qelWyRvm/zVufm5Q%3d
```

<figure><img src="/files/4538d16f0d260f5339942fdd27efd01ec9cdd34e" alt=""><figcaption></figcaption></figure>

#### 绕过身份验证

最后步骤：

1. 删除现有的会话 cookie。
2. 替换 cookie 的值 \*\*
3. 刷新页面。

<figure><img src="/files/8b7c5d96288e772cb0dad0815b4a189ac9c88a64" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/zh/web/business-logic/bypassing-authentication-via-encryption-oracle.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
