TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

KeyChair: Extract RSA private keys out of .keychain files

25 点作者 rgawdzik超过 9 年前

3 条评论

splitbrain超过 9 年前
Hmm a bit more info in the readme would be helpful. My .keychain directory only contains shell snippets that set environment variables to my SSH agent.<p>Where&#x27;s the vulnerability? In ssh-agent? Or are we talking about a completely different keychain tool here?
评论 #10181330 未加载
评论 #10181316 未加载
j_s超过 9 年前
Another project (written in Python) apparently created about a year ago includes more links in the source to all the various Apple open source resources that document the KeyChain format:<p><a href="https:&#x2F;&#x2F;github.com&#x2F;n0fate&#x2F;chainbreaker" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;n0fate&#x2F;chainbreaker</a><p>I would have to dig quite a bit further to determine what is meant by &quot;even the seemingly unextractable ones&quot; in the README and whether or not this Python tool accomplishes the same. (My guess would be yes since it additionally supports decrypting the keychain using the in-memory master key.)<p>It was interesting to me to see what popped up when searching for the RFC 3217 (Triple-DES and RC2 Key Wrapping) IV:<p><a href="https:&#x2F;&#x2F;www.google.com&#x2F;search?q=4adda22c79e82105" rel="nofollow">https:&#x2F;&#x2F;www.google.com&#x2F;search?q=4adda22c79e82105</a><p>The oldest was a keychain extractor written by Matt Johnston (the author of Dropbear) copyright 2004 but only available via the Internet Archive back to 2011: <a href="https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20110228153630&#x2F;http:&#x2F;&#x2F;www.ucc.asn.au&#x2F;~matt&#x2F;src&#x2F;extractkeychain-0.1&#x2F;extractkeychain.py" rel="nofollow">https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20110228153630&#x2F;http:&#x2F;&#x2F;www.ucc.as...</a>
davvolun超过 9 年前
Can we get the title updated to say &#x27;...keys out of OS X .keychain files&#x27;, something like that? I feel like there&#x27;s enough different keychain programs out there, it seemed confusing to me.