[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fhUo-ox045aWvuVxAH9CEMgfdAe8ZKIig6jw9aI4iYKc":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},911,"What are the differences between Chrome and Firefox offline password extraction techniques?","Chrome uses Windows DPAPI to encrypt saved passwords, requiring the user's Master Key and login password for offline decryption. Firefox, on the other hand, uses its own key storage, often based on the Network Security Services (NSS) library. For Firefox, you may need to export the key database or use tools like the Firefox profile decryption method described in [Penetration Techniques - Exporting Saved Passwords from Firefox Browser](\u002Fnews\u002Fpenetration-techniques-exporting-saved-passwords-from-firefox-browser) and [Exporting saved passwords from Firefox browser via Network Security Services](\u002Fnews\u002Fexporting-saved-passwords-from-firefox-browser-via-network-security-services).","\u003Cp>Chrome uses Windows DPAPI to encrypt saved passwords, requiring the user&#39;s Master Key and login password for offline decryption. Firefox, on the other hand, uses its own key storage, often based on the Network Security Services (NSS) library. For Firefox, you may need to export the key database or use tools like the Firefox profile decryption method described in [Penetration Techniques - Exporting Saved Passwords from Firefox Browser](\u002Fnews\u002Fpenetration-techniques-exporting-saved-passwords-from-firefox-browser) and [Exporting saved passwords from Firefox browser via Network Security Services](\u002Fnews\u002Fexporting-saved-passwords-from-firefox-browser-via-network-security-services).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-offline-export-of-passwords-saved-in-chrome-browser\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-differences-between-chrome-and-firefox-offline-password-extraction--1777481451735","Chrome vs Firefox, offline extraction, DPAPI, NSS, password export",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},221,"Penetration Techniques - Offline Export of Passwords Saved in Chrome Browser","penetration-techniques-offline-export-of-passwords-saved-in-chrome-browser","Learn how to export Chrome saved passwords offline using DPAPI, NTLM hash, and Master Key decryption techniques for penetration testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Penetration Techniques - Exporting Passwords Saved in Chrome Browser', the principles and methods for exporting Chrome browser passwords were introduced. A question was raised at the end:\u003Cstrong>If only the user's NTLM hash is obtained, can the plaintext passwords saved in the Chrome browser be exported?\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>There are few references on this topic, and answering this question requires an understanding of encryption and decryption principles. Therefore, this article attempts to introduce this aspect and draw a final conclusion.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to DPAPI and Related Concepts\u003C\u002Fli>\u003Cli>DPAPI Encryption and Decryption Process\u003C\u002Fli>\u003Cli>Principles of Offline Export\u003C\u002Fli>\u003Cli>Methods for Offline Export\u003C\u002Fli>\u003Cli>Drawing the Final Conclusion\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to DPAPI\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This section references the following links, incorporating personal understanding:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fms995355.aspx\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.passcape.com\u002Findex.php?section=docsys&amp;cmd=details&amp;id=28\u003C\u002Fp>\u003Cp>DPAPI stands for Data Protection Application Programming Interface\u003C\u002Fp>\u003Cp>Widely used as a data protection interface in the Windows system\u003C\u002Fp>\u003Cp>Primarily used to protect encrypted data, common applications include:\u003C\u002Fp>\u003Cul>\u003Cli>EFS file encryption\u003C\u002Fli>\u003Cli>Storing wireless connection passwords\u003C\u002Fli>\u003Cli>Windows Credential Manager\u003C\u002Fli>\u003Cli>Internet Explorer\u003C\u002Fli>\u003Cli>Outlook\u003C\u002Fli>\u003Cli>Skype\u003C\u002Fli>\u003Cli>Windows CardSpace\u003C\u002Fli>\u003Cli>Windows Vault\u003C\u002Fli>\u003Cli>Google Chrome\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Simple to use: encryption employs the CryptProtectData function, decryption uses CryptUnprotectData, with the system automatically handling other complex cryptographic operations in the background.\u003C\u002Fp>\u003Cp>For details on CryptProtectData, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwindows\u002Fdesktop\u002Faa380261(v=vs.85).aspx\u003C\u002Fp>\u003Cp>For details on CryptUnprotectData, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwindows\u002Fdesktop\u002Faa380882(v=vs.85).aspx\u003C\u002Fp>\u003Ch3>Technical Terms\u003C\u002Fh3>\u003Ch4>DPAPI blob:\u003C\u002Fh4>\u003Cp>A ciphertext segment that can be decrypted using a Master Key.\u003C\u002Fp>\u003Cp>Structure as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017321560_0_b24c1c5adb.jpeg\">\u003C\u002Fp>\u003Cp>This image is sourced from https:\u002F\u002Fwww.passcape.com\u002Findex.php?section=docsys&amp;cmd=details&amp;id=28\u003C\u002Fp>\u003Ch4>Master Key:\u003C\u002Fh4>\u003Cp>64 bytes, used to decrypt DPAPI blobs.\u003C\u002Fp>\u003Cp>Encrypted with the user's login password, SID, and a 16-byte random number, then stored in the Master Key file.\u003C\u002Fp>\u003Ch4>Master Key file：\u003C\u002Fh4>\u003Cp>Binary file that can be decrypted using the user's login password to obtain the Master Key\u003C\u002Fp>\u003Cp>Contains the following five parts：\u003C\u002Fp>\u003Cul>\u003Cli>Header and system information\u003C\u002Fli>\u003Cli>User's Master Key\u003C\u002Fli>\u003Cli>Local backup encryption key\u003C\u002Fli>\u003Cli>Unique CREDHIST file identifier\u003C\u002Fli>\u003Cli>Domain Master Key backup\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Located at a fixed path： %APPDATA%\\Microsoft\\Protect\\%SID%\u003C\u002Fp>\u003Cp>For example：\u003C\u002Fp>\u003Cp>C:\\Users\\a\\AppData\\Roaming\\Microsoft\\Protect\\S-1-5-21-3453529135-4164765056-1075703908-1001\u003C\u002Fp>\u003Cp>Contains the file 329c4147-0011-4ad6-829d-e32dcbd1bbd7 (system file, hidden attribute)\u003C\u002Fp>\u003Cp>Cannot be viewed directly\u003C\u002Fp>\u003Cp>Can be parsed using mimikatz with the following command：\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe log \"dpapi::masterkey \u002Fin:\"329c4147-0011-4ad6-829d-e32dcbd1bbd7\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz(commandline) # dpapi::masterkey \u002Fin:329c4147-0011-4ad6-829d-e32dcbd1bbd7\u003Cbr>**MASTERKEYS**\u003Cbr>  dwVersion          : 00000002 - 2\u003Cbr>  szGuid             : {329c4147-0011-4ad6-829d-e32dcbd1bbd7}\u003Cbr>  dwFlags            : 00000005 - 5\u003Cbr>  dwMasterKeyLen     : 000000b0 - 176\u003Cbr>  dwBackupKeyLen     : 00000090 - 144\u003Cbr>  dwCredHistLen      : 00000014 - 20\u003Cbr>  dwDomainKeyLen     : 00000000 - 0\u003Cbr>[masterkey]\u003Cbr>  **MASTERKEY**\u003Cbr>    dwVersion        : 00000002 - 2\u003Cbr>    salt             : 9917a47f1949226e4e8c5b8a3aaf4808\u003Cbr>    rounds           : 00000ce4 - 3300\u003Cbr>    algHash          : 0000800e - 32782 (CALG_SHA_512)\u003Cbr>    algCrypt         : 00006610 - 26128 (CALG_AES_256)\u003Cbr>    pbKey            : cf2634535384431da063fd9a240ab575d13dc1daee8ea545d5c9a0628fa5cc63cf825b3b24642b3d7fe98a3703c1e7cdc7e49132a017e3e45fe34f8512fdb8b224e5c30a754683ff6e098a94a1ee396c026a6022323aff6903b3cdad1185a719accadb924f80482dcf426996fb3f662323d7c9e885504f39baa080d63eaddd2621171b3d780cef9c47d9a0b79a4afc20\u003Cbr>\u003Cbr>[backupkey]\u003Cbr>  **MASTERKEY**\u003Cbr>    dwVersion        : 00000002 - 2\u003Cbr>    salt             : 57fb6f4228e9ca7d686c7f174f1691b0\u003Cbr>    rounds           : 00000ce4 - 3300\u003Cbr>    algHash          : 0000800e - 32782 (CALG_SHA_512)\u003Cbr>    algCrypt         : 00006610 - 26128 (CALG_AES_256)\u003Cbr>    pbKey            : 1ae34b8395375465871a999c0d04365cc5089cad4bea139344ecb8f9cf0da1abe5d7b096e9594506a0d8c772469b1f81118d608823e2be33020a8a86bb6d190d61865d270e299dfec9aca011531313dd2a2cd6dc4a53adc77b17a410d15ac4c6b11b3450d1c9739e869f67a8278d60ee\u003Cbr>\u003Cbr>[credhist]\u003Cbr>  **CREDHIST INFO**\u003Cbr>    dwVersion        : 00000003 - 3\u003Cbr>    guid             : {58680bc7-055e-4728-ab96-c34d64c565f2}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 DPAPI Decryption Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Use the user's login password to decrypt the Master Key file and obtain the Master Key\u003C\u002Fh3>\u003Cp>Fixed location: There are often multiple Master Key files under %APPDATA%\\Microsoft\\Protect\\%SID%\u003C\u002Fp>\u003Cp>For security reasons, the system automatically generates a new Master Key every 90 days (old ones are not deleted)\u003C\u002Fp>\u003Cp>Under %APPDATA%\\Microsoft\\Protect\\%SID%, there is a fixed file named Preferred, which contains the name and creation time of the latest Master Key file. The file structure is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>typedef struct _tagPreferredMasterKey\u003Cbr>{\u003Cbr>  GUID guidMasterKey;\u003Cbr>  FILETIME ftCreated;\u003Cbr>} PREFERREDMASTERKEY, *PPREFERREDMASTERKEY;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Use the Master Key to decrypt the DPAPI blob and obtain the plaintext\u003C\u002Fh3>\u003Ch2>0x04 Offline Extraction of Passwords Saved in Chrome Browser\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Obtain the DPAPI blob\u003C\u002Fh3>\u003Cp>The DPAPI blob is located in the password field of the SQLite database file 'Login Data', as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017370980_1_27c79d2743.jpeg\">\u003C\u002Fp>\u003Cp>Use a Python script to read it and save it to a file, with the code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>from os import getenv\u003Cbr>import sqlite3\u003Cbr>import binascii\u003Cbr>conn = sqlite3.connect(\"Login Data\")\u003Cbr>cursor = conn.cursor()\u003Cbr>cursor.execute('SELECT action_url, username_value, password_value FROM logins')\u003Cbr>for result in cursor.fetchall():\u003Cbr>    print (binascii.b2a_hex(result[2]))\u003Cbr>    f = open('test.txt', 'wb')\u003Cbr>    f.write(result[2])\u003Cbr>    f.close()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Decrypt the Master Key to obtain the plaintext\u003C\u002Fh3>\u003Cp>Use the tool Windows Password Recovery, download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.passcape.com\u002Findex.php?section=downloads&amp;category=28\u003C\u002Fp>\u003Cp>Select Utils -&gt; DPAPI Decoder and Analyser -&gt; Decrypt DPAPI data blob\u003C\u002Fp>\u003Cp>Set DPAPI blob file to point to the saved DPAPI blob file test.txt, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017394785_2_4565c698fe.jpeg\">\u003C\u002Fp>\u003Cp>Set Master Key file to point to the Master Key file to be cracked, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017437642_3_8205c50241.jpeg\">\u003C\u002Fp>\u003Cp>Next, enter the user login password\u003C\u002Fp>\u003Cp>Obtain the plaintext, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017466527_4_a1261a674f.jpeg\">\u003C\u002Fp>\u003Cp>Successfully decrypted\u003C\u002Fp>\u003Cp>Use ChromePass to verify the results\u003C\u002Fp>\u003Cp>ChromePass download link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.nirsoft.net\u002Futils\u002Fchromepass.html\u003C\u002Fp>\u003Cp>Parameter description:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fexternal \u003Cuser profile=\"\" path=\"\"> \u003Clast log-on=\"\" password=\"\">\u003C\u002Flast>\u003C\u002Fuser>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ChromePass.exe \u002Fexternal c:\\1\\2\\3\\ test123 \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017480941_5_60a4877c7c.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Final Conclusion\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Unable to automatically locate the Master Key file\u003C\u002Fh3>\u003Cp>If the user SID folder contains multiple Master Key files, when using Windows Password Recovery to attempt decryption, each must be tested individually. Alternatively, the corresponding Master Key file can be identified by reading the first 16 bytes of the file's Preferred attribute.\u003C\u002Fp>\u003Cp>This issue does not exist with ChromePass; simply enter the path of the parent directory of the file.\u003C\u002Fp>\u003Ch3>2. Unable to decrypt the Master Key using the NTLM hash of the user's login password\u003C\u002Fh3>\u003Cp>The current version of DPAPI has been designed with this vulnerability in mind, utilizing the SHA1 algorithm (whereas NTLM hash uses MD4 encryption).\u003C\u002Fp>\u003Cp>Therefore, it is not possible to decrypt the Master Key using the NTLM hash of the user's login password.\u003C\u002Fp>\u003Ch3>3. DPAPI is secure and meets password security requirements\u003C\u002Fh3>\u003Cp>The above tests are based on having already obtained access to the target system, meaning the target system is already compromised.\u003C\u002Fp>\u003Cp>For a Windows system without access, using DPAPI currently does not cause password cracking issues.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>By analyzing the DPAPI encryption and decryption process, this article concludes: Using the user's NTLM hash, it is impossible to export plaintext passwords saved in the Chrome browser.\u003C\u002Fp>\u003Ch2>0x07 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Offline export of passwords saved in the Chrome browser can also be achieved by extracting the Master Key from the lsass process for decryption, without needing the user's plaintext password. For details, refer to 'Penetration Techniques—Offline Export of Passwords Saved in Chrome Browser Using Masterkey'.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Penetration Techniques - Exporting Passwords Saved in Chrome Browser', the principles and methods for exporting Chrome browser passwords were introduced. A question was raised at the end:\u003Cstrong>If only the user's NTLM hash is obtained, can the plaintext passwords saved in the Chrome browser be exported?\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>There are few references on this topic, and answering this question requires an understanding of encryption and decryption principles. Therefore, this article attempts to introduce this aspect and draw a final conclusion.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to DPAPI and Related Concepts\u003C\u002Fli>\u003Cli>DPAPI Encryption and Decryption Process\u003C\u002Fli>\u003Cli>Principles of Offline Export\u003C\u002Fli>\u003Cli>Methods for Offline Export\u003C\u002Fli>\u003Cli>Drawing the Final Conclusion\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to DPAPI\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This section references the following links, incorporating personal understanding:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fms995355.aspx\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.passcape.com\u002Findex.php?section=docsys&amp;cmd=details&amp;id=28\u003C\u002Fp>\u003Cp>DPAPI stands for Data Protection Application Programming Interface\u003C\u002Fp>\u003Cp>Widely used as a data protection interface in the Windows system\u003C\u002Fp>\u003Cp>Primarily used to protect encrypted data, common applications include:\u003C\u002Fp>\u003Cul>\u003Cli>EFS file encryption\u003C\u002Fli>\u003Cli>Storing wireless connection passwords\u003C\u002Fli>\u003Cli>Windows Credential Manager\u003C\u002Fli>\u003Cli>Internet Explorer\u003C\u002Fli>\u003Cli>Outlook\u003C\u002Fli>\u003Cli>Skype\u003C\u002Fli>\u003Cli>Windows CardSpace\u003C\u002Fli>\u003Cli>Windows Vault\u003C\u002Fli>\u003Cli>Google Chrome\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Simple to use: encryption employs the CryptProtectData function, decryption uses CryptUnprotectData, with the system automatically handling other complex cryptographic operations in the background.\u003C\u002Fp>\u003Cp>For details on CryptProtectData, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwindows\u002Fdesktop\u002Faa380261(v=vs.85).aspx\u003C\u002Fp>\u003Cp>For details on CryptUnprotectData, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwindows\u002Fdesktop\u002Faa380882(v=vs.85).aspx\u003C\u002Fp>\u003Ch3>Technical Terms\u003C\u002Fh3>\u003Ch4>DPAPI blob:\u003C\u002Fh4>\u003Cp>A ciphertext segment that can be decrypted using a Master Key.\u003C\u002Fp>\u003Cp>Structure as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017321560_0_b24c1c5adb-1.jpeg\">\u003C\u002Fp>\u003Cp>This image is sourced from https:\u002F\u002Fwww.passcape.com\u002Findex.php?section=docsys&amp;cmd=details&amp;id=28\u003C\u002Fp>\u003Ch4>Master Key:\u003C\u002Fh4>\u003Cp>64 bytes, used to decrypt DPAPI blobs.\u003C\u002Fp>\u003Cp>Encrypted with the user's login password, SID, and a 16-byte random number, then stored in the Master Key file.\u003C\u002Fp>\u003Ch4>Master Key file：\u003C\u002Fh4>\u003Cp>Binary file that can be decrypted using the user's login password to obtain the Master Key\u003C\u002Fp>\u003Cp>Contains the following five parts：\u003C\u002Fp>\u003Cul>\u003Cli>Header and system information\u003C\u002Fli>\u003Cli>User's Master Key\u003C\u002Fli>\u003Cli>Local backup encryption key\u003C\u002Fli>\u003Cli>Unique CREDHIST file identifier\u003C\u002Fli>\u003Cli>Domain Master Key backup\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Located at a fixed path： %APPDATA%\\Microsoft\\Protect\\%SID%\u003C\u002Fp>\u003Cp>For example：\u003C\u002Fp>\u003Cp>C:\\Users\\a\\AppData\\Roaming\\Microsoft\\Protect\\S-1-5-21-3453529135-4164765056-1075703908-1001\u003C\u002Fp>\u003Cp>Contains the file 329c4147-0011-4ad6-829d-e32dcbd1bbd7 (system file, hidden attribute)\u003C\u002Fp>\u003Cp>Cannot be viewed directly\u003C\u002Fp>\u003Cp>Can be parsed using mimikatz with the following command：\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe log \"dpapi::masterkey \u002Fin:\"329c4147-0011-4ad6-829d-e32dcbd1bbd7\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz(commandline) # dpapi::masterkey \u002Fin:329c4147-0011-4ad6-829d-e32dcbd1bbd7\u003Cbr>**MASTERKEYS**\u003Cbr>  dwVersion          : 00000002 - 2\u003Cbr>  szGuid             : {329c4147-0011-4ad6-829d-e32dcbd1bbd7}\u003Cbr>  dwFlags            : 00000005 - 5\u003Cbr>  dwMasterKeyLen     : 000000b0 - 176\u003Cbr>  dwBackupKeyLen     : 00000090 - 144\u003Cbr>  dwCredHistLen      : 00000014 - 20\u003Cbr>  dwDomainKeyLen     : 00000000 - 0\u003Cbr>[masterkey]\u003Cbr>  **MASTERKEY**\u003Cbr>    dwVersion        : 00000002 - 2\u003Cbr>    salt             : 9917a47f1949226e4e8c5b8a3aaf4808\u003Cbr>    rounds           : 00000ce4 - 3300\u003Cbr>    algHash          : 0000800e - 32782 (CALG_SHA_512)\u003Cbr>    algCrypt         : 00006610 - 26128 (CALG_AES_256)\u003Cbr>    pbKey            : cf2634535384431da063fd9a240ab575d13dc1daee8ea545d5c9a0628fa5cc63cf825b3b24642b3d7fe98a3703c1e7cdc7e49132a017e3e45fe34f8512fdb8b224e5c30a754683ff6e098a94a1ee396c026a6022323aff6903b3cdad1185a719accadb924f80482dcf426996fb3f662323d7c9e885504f39baa080d63eaddd2621171b3d780cef9c47d9a0b79a4afc20\u003Cbr>\u003Cbr>[backupkey]\u003Cbr>  **MASTERKEY**\u003Cbr>    dwVersion        : 00000002 - 2\u003Cbr>    salt             : 57fb6f4228e9ca7d686c7f174f1691b0\u003Cbr>    rounds           : 00000ce4 - 3300\u003Cbr>    algHash          : 0000800e - 32782 (CALG_SHA_512)\u003Cbr>    algCrypt         : 00006610 - 26128 (CALG_AES_256)\u003Cbr>    pbKey            : 1ae34b8395375465871a999c0d04365cc5089cad4bea139344ecb8f9cf0da1abe5d7b096e9594506a0d8c772469b1f81118d608823e2be33020a8a86bb6d190d61865d270e299dfec9aca011531313dd2a2cd6dc4a53adc77b17a410d15ac4c6b11b3450d1c9739e869f67a8278d60ee\u003Cbr>\u003Cbr>[credhist]\u003Cbr>  **CREDHIST INFO**\u003Cbr>    dwVersion        : 00000003 - 3\u003Cbr>    guid             : {58680bc7-055e-4728-ab96-c34d64c565f2}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 DPAPI Decryption Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Use the user's login password to decrypt the Master Key file and obtain the Master Key\u003C\u002Fh3>\u003Cp>Fixed location: There are often multiple Master Key files under %APPDATA%\\Microsoft\\Protect\\%SID%\u003C\u002Fp>\u003Cp>For security reasons, the system automatically generates a new Master Key every 90 days (old ones are not deleted)\u003C\u002Fp>\u003Cp>Under %APPDATA%\\Microsoft\\Protect\\%SID%, there is a fixed file named Preferred, which contains the name and creation time of the latest Master Key file. The file structure is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>typedef struct _tagPreferredMasterKey\u003Cbr>{\u003Cbr>  GUID guidMasterKey;\u003Cbr>  FILETIME ftCreated;\u003Cbr>} PREFERREDMASTERKEY, *PPREFERREDMASTERKEY;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Use the Master Key to decrypt the DPAPI blob and obtain the plaintext\u003C\u002Fh3>\u003Ch2>0x04 Offline Extraction of Passwords Saved in Chrome Browser\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Obtain the DPAPI blob\u003C\u002Fh3>\u003Cp>The DPAPI blob is located in the password field of the SQLite database file 'Login Data', as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017370980_1_27c79d2743-1.jpeg\">\u003C\u002Fp>\u003Cp>Use a Python script to read it and save it to a file, with the code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>from os import getenv\u003Cbr>import sqlite3\u003Cbr>import binascii\u003Cbr>conn = sqlite3.connect(\"Login Data\")\u003Cbr>cursor = conn.cursor()\u003Cbr>cursor.execute('SELECT action_url, username_value, password_value FROM logins')\u003Cbr>for result in cursor.fetchall():\u003Cbr>    print (binascii.b2a_hex(result[2]))\u003Cbr>    f = open('test.txt', 'wb')\u003Cbr>    f.write(result[2])\u003Cbr>    f.close()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Decrypt the Master Key to obtain the plaintext\u003C\u002Fh3>\u003Cp>Use the tool Windows Password Recovery, download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.passcape.com\u002Findex.php?section=downloads&amp;category=28\u003C\u002Fp>\u003Cp>Select Utils -&gt; DPAPI Decoder and Analyser -&gt; Decrypt DPAPI data blob\u003C\u002Fp>\u003Cp>Set DPAPI blob file to point to the saved DPAPI blob file test.txt, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017394785_2_4565c698fe-1.jpeg\">\u003C\u002Fp>\u003Cp>Set Master Key file to point to the Master Key file to be cracked, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017437642_3_8205c50241-1.jpeg\">\u003C\u002Fp>\u003Cp>Next, enter the user login password\u003C\u002Fp>\u003Cp>Obtain the plaintext, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017466527_4_a1261a674f-1.jpeg\">\u003C\u002Fp>\u003Cp>Successfully decrypted\u003C\u002Fp>\u003Cp>Use ChromePass to verify the results\u003C\u002Fp>\u003Cp>ChromePass download link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.nirsoft.net\u002Futils\u002Fchromepass.html\u003C\u002Fp>\u003Cp>Parameter description:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fexternal \u003Cuser profile=\"\" path=\"\"> \u003Clast log-on=\"\" password=\"\">\u003C\u002Flast>\u003C\u002Fuser>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ChromePass.exe \u002Fexternal c:\\1\\2\\3\\ test123 \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017480941_5_60a4877c7c-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Final Conclusion\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Unable to automatically locate the Master Key file\u003C\u002Fh3>\u003Cp>If the user SID folder contains multiple Master Key files, when using Windows Password Recovery to attempt decryption, each must be tested individually. Alternatively, the corresponding Master Key file can be identified by reading the first 16 bytes of the file's Preferred attribute.\u003C\u002Fp>\u003Cp>This issue does not exist with ChromePass; simply enter the path of the parent directory of the file.\u003C\u002Fp>\u003Ch3>2. Unable to decrypt the Master Key using the NTLM hash of the user's login password\u003C\u002Fh3>\u003Cp>The current version of DPAPI has been designed with this vulnerability in mind, utilizing the SHA1 algorithm (whereas NTLM hash uses MD4 encryption).\u003C\u002Fp>\u003Cp>Therefore, it is not possible to decrypt the Master Key using the NTLM hash of the user's login password.\u003C\u002Fp>\u003Ch3>3. DPAPI is secure and meets password security requirements\u003C\u002Fh3>\u003Cp>The above tests are based on having already obtained access to the target system, meaning the target system is already compromised.\u003C\u002Fp>\u003Cp>For a Windows system without access, using DPAPI currently does not cause password cracking issues.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>By analyzing the DPAPI encryption and decryption process, this article concludes: Using the user's NTLM hash, it is impossible to export plaintext passwords saved in the Chrome browser.\u003C\u002Fp>\u003Ch2>0x07 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Offline export of passwords saved in the Chrome browser can also be achieved by extracting the Master Key from the lsass process for decryption, without needing the user's plaintext password. For details, refer to 'Penetration Techniques—Offline Export of Passwords Saved in Chrome Browser Using Masterkey'.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",652,"Onedaysec",5,"published","2026-02-02T07:38:21.177Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Offline Chrome Password Export via DPAPI & NTLM Hash Techniques","DPAPI, Chrome password export, offline decryption, NTLM hash, Windows security, penetration testing, CryptProtectData, Master Key, mimikatz",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46],910,909,908,{"title":39,"description":39,"image":39},"2026-07-24T15:37:10.871Z","2026-07-23T16:02:15.550Z","draft","2026-07-23T16:15:29.432Z"]