问题描述
这几天想抓取godaddy的whois数据碰到了个难题:抓取URL:https://who.godaddy.com/whois.aspx?domain=0.com&prog_id=GoDaddy需要输入验证码而抓取URL:https://who.godaddy.com/whois.aspx?domain=0.com&prog_id=GoDaddy&k=46UX03H2Ju9euL0dIJls3LCq8H/5JhPucTBMRmETIzJ6JwUVDRmPpg==则可以直接跳过验证码阶段。但是小白我对这个加解密方面是一窍不通。这里整合了一些样本,前面域名,后面k参数密文。目测规则明显,希望大神前来为我解答。域名k密文0.tv2rCIberdanCy8iLy0OUeTwi6obtyHSnCx8gja/DsXf8C8gCwgxk1A==0.twUdJiMLHXlx3Cy8iLy0OUeTwi6obtyHSnCx8gja/DsXf8C8gCwgxk1A==0.ccCWP98L3YZALCy8iLy0OUeTwi6obtyHSnCx8gja/DsXf8C8gCwgxk1A==0.coRHoSpi1JDmzCy8iLy0OUeTwi6obtyHSnCx8gja/DsXf8C8gCwgxk1A==0.com46UX03H2Ju9euL0dIJls3LCq8H/5JhPucTBMRmETIzJ6JwUVDRmPpg==0.net8frLGGDSoJheuL0dIJls3LCq8H/5JhPucTBMRmETIzJ6JwUVDRmPpg==0.orgFpGQcXcvXcVeuL0dIJls3LCq8H/5JhPucTBMRmETIzJ6JwUVDRmPpg==00.tvjU2v0rE7brdeuL0dIJls3LCq8H/5JhPucTBMRmETIzJ6JwUVDRmPpg==00.tw46Gjd0VikJeuL0dIJls3LCq8H/5JhPucTBMRmETIzJ6JwUVDRmPpg==00.cc3VzSgh436QReuL0dIJls3LCq8H/5JhPucTBMRmETIzJ6JwUVDRmPpg==00.coxE79JwleuL0dIJls3LCq8H/5JhPucTBMRmETIzJ6JwUVDRmPpg==000.tvHY/NOZo1bCy50TPd7SWMeKT9NbqhVdJkOuRgX3Tr47lp7h0xnKwfQ==000.twC4UchZbui50TPd7SWMeKT9NbqhVdJkOuRgX3Tr47lp7h0xnKwfQ==000.ccQ9NlRxSTn50TPd7SWMeKT9NbqhVdJkOuRgX3Tr47lp7h0xnKwfQ==000.coffZ6Qc9pVES50TPd7SWMeKT9NbqhVdJkOuRgX3Tr47lp7h0xnKwfQ==00.compqQLcS3HOVO50TPd7SWMeKT9NbqhVdJkOuRgX3Tr47lp7h0xnKwfQ==00.net0gEtxv8ctUe50TPd7SWMeKT9NbqhVdJkOuRgX3Tr47lp7h0xnKwfQ==00.orgyVS/XZOMMva50TPd7SWMeKT9NbqhVdJkOuRgX3Tr47lp7h0xnKwfQ==0.infotWyFnj/nddy50TPd7SWMeKT9NbqhVdJkOuRgX3Tr47lp7h0xnKwfQ==0000.tvWxtAKGb9oYs4/eAHv81yokymcdxGf5V9zTOhZpvpt3xDwIyfM4PcNg==0000.twZpZ5rohdZcw4/eAHv81yokymcdxGf5V9zTOhZpvpt3xDwIyfM4PcNg==0000.ccrKk/khkXf2A4/eAHv81yokymcdxGf5V9zTOhZpvpt3xDwIyfM4PcNg==0000.colakhqF9D9oY4/eAHv81yokymcdxGf5V9zTOhZpvpt3xDwIyfM4PcNg==000.coms7eMxeJzKQY4/eAHv81yokymcdxGf5V9zTOhZpvpt3xDwIyfM4PcNg==000.netNQm22xyT5Yg4/eAHv81yokymcdxGf5V9zTOhZpvpt3xDwIyfM4PcNg==000.orgd66y7mEzcM4/eAHv81yokymcdxGf5V9zTOhZpvpt3xDwIyfM4PcNg==00.infoW3Oxynh9T1w4/eAHv81yokymcdxGf5V9zTOhZpvpt3xDwIyfM4PcNg==00000.tvWVFyDj9e/Q6MU4TguR6M7byld9kiZ262mZTJJRaUQZtMQwnazNUxv4kyd2jcdcRB00000.tweaZJJAnNvCMU4TguR6M7byld9kiZ262mZTJJRaUQZtMQwnazNUxv4kyd2jcdcRB00000.cc4noCptFvL2MU4TguR6M7byld9kiZ262mZTJJRaUQZtMQwnazNUxv4kyd2jcdcRB00000.coLjfq9g179lGMU4TguR6M7byld9kiZ262mZTJJRaUQZtMQwnazNUxv4kyd2jcdcRB0000.comZ0EOCSr4tCMU4TguR6M7byld9kiZ262mZTJJRaUQZtMQwnazNUxv4kyd2jcdcRB0000.netMVC7knDd8SKMU4TguR6M7byld9kiZ262mZTJJRaUQZtMQwnazNUxv4kyd2jcdcRB0000.orgwv0xSFl8ileMU4TguR6M7byld9kiZ262mZTJJRaUQZtMQwnazNUxv4kyd2jcdcRB000.infofOHFDUFEDRmMU4TguR6M7byld9kiZ262mZTJJRaUQZtMQwnazNUxv4kyd2jcdcRB000000.tvSG8RYawc9YR1wQVNtw2jGGMfDj/PnBN7fwNkg0YtBRsC9jhepqjiBdOeAi/HF7000000.twSG8RYawc9YSjnBUrDVg0GMfDj/PnBN7fwNkg0YtBRsC9jhepqjiBdOeAi/HF7000000.cc/ylEerBdPO0HTAHpM9JKmMfDj/PnBN7fwNkg0YtBRsC9jhepqjiBdOeAi/HF7000000.co/ylEerBdPO2xpTg8BVP7FmMfDj/PnBN7fwNkg0YtBRsC9jhepqjiBdOeAi/HF700000.comLjfq9g179lH0QLyMbogb5mMfDj/PnBN7fwNkg0YtBRsC9jhepqjiBdOeAi/HF700000.netxpIt90dW1K05fqrtaTdTGMfDj/PnBN7fwNkg0YtBRsC9jhepqjiBdOeAi/HF700000.orgu1bSPc2AmeC5Dm7BzCYNbWMfDj/PnBN7fwNkg0YtBRsC9jhepqjiBdOeAi/HF70000.infobr7/zHLnrlGxpTg8BVP7FmMfDj/PnBN7fwNkg0YtBRsC9jhepqjiBdOeAi/HF70000000.tvGjxOfOn7xBUoL2Qb3G/19PLn8FNzGUbkbQDzea0vTdAKt3ZnQwPcuAeqfWCkB0S00000000.twGjxOfOn7xBVrt9Ya9sr61/Ln8FNzGUbkbQDzea0vTdAKt3ZnQwPcuAeqfWCkB0S00000000.ccGjxOfOn7xBWpQ9jBwpjnUvLn8FNzGUbkbQDzea0vTdAKt3ZnQwPcuAeqfWCkB0S00000000.coGjxOfOn7xBVEXlZfn4AHgfLn8FNzGUbkbQDzea0vTdAKt3ZnQwPcuAeqfWCkB0S0000000.com/ylEerBdPO1en4ioBJ9OBvLn8FNzGUbkbQDzea0vTdAKt3ZnQwPcuAeqfWCkB0S0000000.netBcxlzJ8omQweZZDzPVzc/Ln8FNzGUbkbQDzea0vTdAKt3ZnQwPcuAeqfWCkB0S0000000.orgKFJ2Re7HDLyHIGkg3tsPLn8FNzGUbkbQDzea0vTdAKt3ZnQwPcuAeqfWCkB0S000000.info1ZTfMMCXKgfSKOJvn6rINfLn8FNzGUbkbQDzea0vTdAKt3ZnQwPcuAeqfWCkB0S000000000.tvCV66iIsf8HkN4iQo9HYYCeWp01I3an5iPUWXztbczGWWgoZluf8hBfXB7GSn3YZ00000000.twCV66iIsf8E4QZSIbC9jICeWp01I3an5iPUWXztbczGWWgoZluf8hBfXB7GSn3YZ00000000.ccCV66iIsf8EX9tneCix/gSeWp01I3an5iPUWXztbczGWWgoZluf8hBfXB7GSn3YZ00000000.coCV66iIsf8ELNcvh3LExCeWp01I3an5iPUWXztbczGWWgoZluf8hBfXB7GSn3YZ0000000.comGjxOfOn7xBVFaHdbR8ITCeWp01I3an5iPUWXztbczGWWgoZluf8hBfXB7GSn3YZ0000000.netGjxOfOn7xBW0gDJ58tJEoCeWp01I3an5iPUWXztbczGWWgoZluf8hBfXB7GSn3YZ0000000.orgGjxOfOn7xBWTXnvxr0rUcCeWp01I3an5iPUWXztbczGWWgoZluf8hBfXB7GSn3YZ000000.infoDRjJhNtPV6xKJeJ2wW6aCeWp01I3an5iPUWXztbczGWWgoZluf8hBfXB7GSn3YZ000000000.tvCV66iIsf8HasIht6t1r6cLLyIvLQ5R5PCLqhu3IdKcLHyCNr8Oxd/wLyALCDGTU000000000.twCV66iIsf8FR0mIwsdeXHcLLyIvLQ5R5PCLqhu3IdKcLHyCNr8Oxd/wLyALCDGTU000000000.ccCV66iIsf8EJY/3wvdhkAsLLyIvLQ5R5PCLqhu3IdKcLHyCNr8Oxd/wLyALCDGTU000000000.coCV66iIsf8FEehKmLUkObMLLyIvLQ5R5PCLqhu3IdKcLHyCNr8Oxd/wLyALCDGTU00000000.comCV66iIsf8ESiZpPhTIvsLLyIvLQ5R5PCLqhu3IdKcLHyCNr8Oxd/wLyALCDGTU00000000.netCV66iIsf8FnSomd1c5IV8LLyIvLQ5R5PCLqhu3IdKcLHyCNr8Oxd/wLyALCDGTU00000000.orgCV66iIsf8EzJ3pq43bivMLLyIvLQ5R5PCLqhu3IdKcLHyCNr8Oxd/wLyALCDGTU0000000.infoGjxOfOn7xBWbhLhmQNnaeMLLyIvLQ5R5PCLqhu3IdKcLHyCNr8Oxd/wLyALCDGTU0000000000.tvCV66iIsf8GNTa/SsTtut164vR0gmWzcsKrwf/kmE5xMExGYRMjMnonBRUNGYm0000000000.twCV66iIsf8HjoaN3RWKT4l64vR0gmWzcsKrwf/kmE5xMExGYRMjMnonBRUNGYm0000000000.ccCV66iIsf8HdXNKCHjfpBF64vR0gmWzcsKrwf/kmE5xMExGYRMjMnonBRUNGYm0000000000.coCV66iIsf8HETv3774n7CV64vR0gmWzcsKrwf/kmE5xMExGYRMjMnonBRUNGYm000000000.comCV66iIsf8HjpRfTcfYm7164vR0gmWzcsKrwf/kmE5xMExGYRMjMnonBRUNGYm000000000.netCV66iIsf8HxssYYNKgmF64vR0gmWzcsKrwf/kmE5xMExGYRMjMnonBRUNGYm000000000.orgCV66iIsf8EWkZBxdy9dxV64vR0gmWzcsKrwf/kmE5xMExGYRMjMnonBRUNGYm00000000.infoCV66iIsf8EAruxV/L0/7V64vR0gmWzcsKrwf/kmE5xMExGYRMjMnonBRUNGYm00000000000.tvCV66iIsf8Edj805mjVsLLnRM93tJYx4pP01v6qFV0mQ65GBfdOvjuWnuHTGcrB900000000000.twCV66iIsf8ELhT5z6Flu6LnRM93tJYx4pP01v6qFV0mQ65GBfdOvjuWnuHTGcrB900000000000.ccCV66iIsf8FD02VHH5JOf7nRM93tJYx4pP01v6qFV0mQ65GBfdOvjuWnuHTGcrB900000000000.coCV66iIsf8F99npBz2lURLnRM93tJYx4pP01v6qFV0mQ65GBfdOvjuWnuHTGcrB90000000000.comCV66iIsf8GmpAtxLcc5U7nRM93tJYx4pP01v6qFV0mQ65GBfdOvjuWnuHTGcrB90000000000.netCV66iIsf8HSAS3G/xy1R7nRM93tJYx4pP01v6qFV0mQ65GBfdOvjuWnuHTGcrB90000000000.orgCV66iIsf8HJVL9dk4wy9rnRM93tJYx4pP01v6qFV0mQ65GBfdOvjuWnuHTGcrB9000000000.infoCV66iIsf8G1bIWePd13LnRM93tJYx4pP01v6qFV0mQ65GBfdOvjuWnuHTGcrB90000000000000.tvCV66iIsf8FZUXIOP179DoxThOC5HoztvKV32SJnbraZlMklFpRBm0xDCdrM1TG/iTJ3aNx1xEE=可以看到同等长度的域名密文长度也相同而且还有固定一段密文相同,本人测试过,域名对应的密文是固定的,比如0.com对应46UX03H2Ju9euL0dIJls3LCq8H/5JhPucTBMRmETIzJ6JwUVDRmPpg==,而0.tv对应2rCIberdanCy8iLy0OUeTwi6obtyHSnCx8gja/DsXf8C8gCwgxk1A==是一成不变的与验证码无关。苦思冥想后还是没有办法解开,故在这寻求大神们帮助。。。本人邮箱455059233@qq.com,谢谢各位了
解决方案
解决方案二:
如果真是加密不会这么简单吧
解决方案三:
https://who.godaddy.com/whois.aspx?domain=0.com&prog_id=GoDaddy&k=46UX03H2Ju9euL0dIJls3LCq8H/5JhPucTBMRmETIzJ6JwUVDRmPpg==我试了,没鸟用,还是要验证码
解决方案四:
既然认为是base64密文,先解码看看byte[]output=Convert.FromBase64String(JiaMi);//JiaMi为密文stringJieMi=Encoding.Default.GetString(output);//JieMi为解密后的明文
至于变形,那就不好说了,设计者使用了什么算法,我们无法知道,只能碰运气了
解决方案五:
我测试过很多次呢。确定这些K值不变,想想来只能来这碰碰运气。。。感谢各位的回复
解决方案六:
这个应该是二次加密过了,不是标准的base64,在这之前,还有一次加密。
解决方案七:
引用5楼tanta的回复:
这个应该是二次加密过了,不是标准的base64,在这之前,还有一次加密。
不是base64之后再加密的么?