php代码解密coldfusion加密字符串
我们正在尝试在PHP中添加AES/OFB/NOP来解密coldfusion加密字符串。然而,我们认为更糟糕的是,我们在这里尝试了所有的解决方案,但仍然无法让它工作 这是来自CF的代码php代码解密coldfusion加密字符串,php,encryption,coldfusion,Php,Encryption,Coldfusion,我们正在尝试在PHP中添加AES/OFB/NOP来解密coldfusion加密字符串。然而,我们认为更糟糕的是,我们在这里尝试了所有的解决方案,但仍然无法让它工作 这是来自CF的代码 <cfsetting enablecfoutputonly="Yes"> <!--- Set encoding ---> <cfset k_strCharset="UTF-8"> <cfcontent type="text/html; charset=#k_strChars
<cfsetting enablecfoutputonly="Yes">
<!--- Set encoding --->
<cfset k_strCharset="UTF-8">
<cfcontent type="text/html; charset=#k_strCharset#">
<cfset setEncoding("URL", "#k_strCharset#")>
<cfset setEncoding("FORM", "#k_strCharset#")>
<!--- Get variables --->
<cfif IsDefined("FORM.K1")><cfset fv_strK1="#FORM.K1#"><cfelse><cfset fv_strK1=""></cfif><!--- xxx --->
<cfif IsDefined("FORM.S1")><cfset fv_strS1="#FORM.S1#"><cfelse><cfset fv_strS1=""></cfif>
<cfif IsDefined("FORM.S2")><cfset fv_strS2="#FORM.S2#"><cfelse><cfset fv_strS2=""></cfif>
<!--- Encrypt / Decrypt --->
<cfif fv_strK1 is "xxx">
<cfif fv_strS1 is not "">
<cfset fv_strS2 = Encrypt(fv_strS1, fv_strK1, "AES/OFB/NoPadding", "BASE64")>
<cfelseif fv_strS2 is not "">
<cfset fv_strS1 = Decrypt(fv_strS2, fv_strK1, "AES/OFB/NoPadding", "BASE64")>
</cfif>
<cfset fv_strS3 = "">
<cfset fv_strS4 = "">
<cfset fv_strS5 = "">
</cfif>
<cfsetting enablecfoutputonly="No">
然后我们把php当作
<?php
$z = "bf19zWnbPmJxOvzRuP85Bw==";
$encrypted_string="q2SYE7hWWltsBw5byuwl/IkGmOOm+94=";
$source_text = html_entity_decode(getDecrypt($encrypted_string, $z), ENT_NOQUOTES, 'UTF-8');
//echo trim(mcrypt_decrypt(MCRYPT_RIJNDAEL_128, $key, $data, MCRYPT_MODE_OFB));
echo "<br>" . $z . "<br>";
// echo trim(mcrypt_decrypt(MCRYPT_RIJNDAEL_128, base64_decode($z), base64_decode($encrypted_string), MCRYPT_MODE_OFB, mcrypt_create_iv(mcrypt_get_iv_size(MCRYPT_RIJNDAEL_128, MCRYPT_MODE_OFB), MCRYPT_RAND)));
echo "\n\nPlain-Text:\n" . $source_text . "\n";
// Functions
function getDecrypt($str, $key) {
return ofb_decrypt(base64_decode($str),$key);
}
function ofb_decrypt($str, $key, $iv = ' ' )
{
if ($iv==' ' & strlen($str) < 16)
return false;
$td = mcrypt_module_open(MCRYPT_RIJNDAEL_128, ' ' , MCRYPT_MODE_NOFB, ' ');
//RECEOVER IV
$iv_size = mcrypt_enc_get_iv_size($td);
if (empty($iv)) {
$iv = substr($str,0,$iv_size);
$str = substr($str,$iv_size);
}
// initialize encryption
mcrypt_generic_init($td, $key, $iv);
// decrypt
$decrypted_string = mdecrypt_generic($td, $str);
// terminate decrtypion
mcrypt_generic_deinit($td);
mcrypt_module_close($td);
return $decrypted_string;
}
?>
$encrypted_字符串是使用上面的CF脚本创建的
然后我们得到的结果是�=�����@�&O%NSC��#�P�:�
如果有人能给我一个提示,我将不胜感激
谢谢你我可以使用文档不全的'ncfb'参数对mcrypt_decrypt()进行解密,从而从字符串中获得“测试”(和一些垃圾)。我认为垃圾与块大小有关…一些额外的输入示例会很有帮助
function decryptColdfusionString($key, $data)
{
$retVal = mcrypt_decrypt(
MCRYPT_RIJNDAEL_128,
base64_decode($key),
base64_decode($data),
'ncfb',
'0000000000000000'
);
return $retVal;
}
$key = "bf19zWnbPmJxOvzRuP85Bw==";
$data = "q2SYE7hWWltsBw5byuwl/IkGmOOm+94=";
echo decryptColdfusionString($key, $data) . PHP_EOL;
(我知道这已经有两年了,但万一有人遇到同样的问题……)
OFB模式需要IV。尽管ColdFusion代码没有明确指定IV。解密时必须正确提取IV,否则结果将是胡言乱语。1.首先解码加密的base64字符串。2.然后从解码值中提取IV和数据,并像往常一样解密
PHP:
$key = base64_decode("bf19zWnbPmJxOvzRuP85Bw==");
$encrypted="q2SYE7hWWltsBw5byuwl/IkGmOOm+94=";
$decoded = base64_decode($encrypted);
$ivSize = mcrypt_get_iv_size(MCRYPT_RIJNDAEL_128, MCRYPT_MODE_NOFB);
$iv = substr($decoded, 0, $ivSize);
$data = substr($decoded, $ivSize);
$text = mcrypt_decrypt(MCRYPT_RIJNDAEL_128, $key, $data, MCRYPT_MODE_NOFB, $iv);
testing
结果:
$key = base64_decode("bf19zWnbPmJxOvzRuP85Bw==");
$encrypted="q2SYE7hWWltsBw5byuwl/IkGmOOm+94=";
$decoded = base64_decode($encrypted);
$ivSize = mcrypt_get_iv_size(MCRYPT_RIJNDAEL_128, MCRYPT_MODE_NOFB);
$iv = substr($decoded, 0, $ivSize);
$data = substr($decoded, $ivSize);
$text = mcrypt_decrypt(MCRYPT_RIJNDAEL_128, $key, $data, MCRYPT_MODE_NOFB, $iv);
testing
请看一看,看看是否可以根据您的目的对其进行调整。我的客户机正在使用AES/OFB/nopadding进行CF加密,我应该如何计算?我尝试了很多方法,但没有成功。另一方面,他们没有使用IV./\uU \。非常感谢你的帮助。也许谢谢你。