Skip to content

Commit d9c9d68

Browse files
authored
Merge pull request #183 from blacklanternsecurity/dev
Dev
2 parents 67809f0 + a42e9bc commit d9c9d68

File tree

5 files changed

+175
-166
lines changed

5 files changed

+175
-166
lines changed

badsecrets/modules/jsf_viewstate.py

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -85,7 +85,7 @@ def myfaces_validate_decrypt(self, decrypted):
8585

8686
if b"java." in decrypted:
8787
# instead of b64 encoding and looking for rO0, stay in bytes and look for as many as you can
88-
if b"\xAC\xED\x00\x05" in decrypted and ord(bytes([decrypted[4]])) in list(range(112, 126)):
88+
if b"\xac\xed\x00\x05" in decrypted and ord(bytes([decrypted[4]])) in list(range(112, 126)):
8989
return (True, True, uncompressed)
9090
else:
9191
return (True, False, uncompressed)
@@ -134,7 +134,7 @@ def myfaces_decrypt(self, ct_bytes, password_bytes, dec_algos, hash_sizes):
134134
iv_guesses.append(password_bytes[:16])
135135

136136
iv_guesses.append(dec_algo.block_size * b"\x00")
137-
iv_guesses.append(dec_algo.block_size * b"\xFF")
137+
iv_guesses.append(dec_algo.block_size * b"\xff")
138138
iv_guesses.append(dec_algo.block_size * b"\x61")
139139
iv_guesses.append(dec_algo.block_size * b"\x41")
140140
iv_guesses.append(dec_algo.block_size * b"\x30")

badsecrets/modules/rack2_signedcookies.py

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -49,8 +49,6 @@ def check_secret(self, rack_cookie):
4949

5050
def get_hashcat_commands(self, rack_cookie, *args):
5151
rack_cookie_split = rack_cookie.rsplit("--", 1)
52-
print("rack_cookie")
53-
print(rack_cookie_split)
5452
return [
5553
{
5654
"command": f"hashcat -m 150 -a 0 {rack_cookie_split[1]}:{base64.b64decode(unquote(rack_cookie_split[0])).hex()} --hex-salt <dictionary_file>",

0 commit comments

Comments
 (0)