Code Monkey home page Code Monkey logo

bw-dump's People

Contributors

markuta avatar rekitto avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar

bw-dump's Issues

Search pattern different for each master password

There is an issue with the latest version with how it searches for patterns in memory. I've realised that each master password has a unique prefix (4-bytes long) pattern that is just before the plaintext password. This is a problem because the tool currently searches for my old master password prefix, which obviously won't find other master passwords.

I need to figure out a better way to do this.

[?] Wording Question in Description

"A proof-of-concept tool that extracts the master password from a locked Bitwarden vault (must be unlocked at least once) from Windows systems, without requiring administrative privileges. Only Windows platforms have been tested."

Bolded section, does this mean for the CURRENT session ONLY, or will an existing session from prior restarts work (if so isnt working for me).

Had a system with .7.0 on it (downgraded to .2.0 when it didnt work the first time) but it didnt not work.
BW Desktop is currently signed in and the lock is with a pin no longer the master password.
Locking/Unlocking with the Pin doesnt work.

I think the wording meant to imply in the current session vs after a restart or with lock w/pin setup.

Exclude known Bitwarden Desktop strings from output

The tool currently includes ALL strings that match a specific pattern. This means other strings that are obliviously NOT the master password are also included. One quick solution is to retrieve all default strings from a Bitwarden.exe binary which are 8+ characters (minimum password length for registration), and do a compare and exclude.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.