mirror of
https://github.com/nelsbrock/fingerprunk.git
synced 2026-08-15 00:16:47 +02:00
Compare commits
7
Commits
0.2.0
..
c6b5020795
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c6b5020795
|
||
|
|
c74dcd0f01
|
||
|
|
06e528ac09
|
||
|
|
890d8fa0be
|
||
|
|
112a6b087b
|
||
|
|
fe984f2e43
|
||
|
|
b1450070d1
|
Generated
+531
-444
File diff suppressed because it is too large
Load Diff
+7
-7
@@ -1,6 +1,6 @@
|
||||
[package]
|
||||
name = "fingerprunk"
|
||||
version = "0.2.0"
|
||||
version = "0.3.0"
|
||||
authors = ["Niklas Elsbrock <mail@nelsbrock.de>"]
|
||||
edition = "2024"
|
||||
description = "CLI tool for brute-forcing OpenPGP keys with cool fingerprints"
|
||||
@@ -10,11 +10,11 @@ keywords = ["fingerprint", "openpgp", "bruteforce"]
|
||||
categories = ["command-line-utilities"]
|
||||
|
||||
[dependencies]
|
||||
anyhow = "1.0.100"
|
||||
clap = { version = "4.5.50", features = ["derive"] }
|
||||
ctrlc = "3.5.0"
|
||||
fancy-regex = "0.16.2"
|
||||
anyhow = "1.0.102"
|
||||
clap = { version = "4.6.1", features = ["derive"] }
|
||||
ctrlc = "3.5.2"
|
||||
fancy-regex = "0.18.0"
|
||||
num-integer = "0.1.46"
|
||||
num_cpus = "1.17.0"
|
||||
rpassword = "7.4.0"
|
||||
sequoia-openpgp = "2.0.0"
|
||||
rpassword = "7.5.2"
|
||||
sequoia-openpgp = "2.2.0"
|
||||
|
||||
@@ -18,11 +18,11 @@ at `secret.asc`. The regex for this is `^C0FFEE`. Now, simply use the following
|
||||
the search:
|
||||
|
||||
```sh
|
||||
fingerprunk -r '^C0FFEE' >> secret.asc
|
||||
fingerprunk -r '^C0FFEE' -u "Your Name <your.email@example.org>" >> secret.asc
|
||||
```
|
||||
|
||||
Fingerprunk will now generate many keys and write out all keys with matching fingerprints to
|
||||
standard output (here: `secret.asc`).
|
||||
standard output (here: `secret.asc`), adding the provided user ID.
|
||||
|
||||
If you want Fingerprunk to output password-encrypted keys use the `-p` flag and you will be prompted
|
||||
for a password.
|
||||
|
||||
+49
-18
@@ -9,7 +9,7 @@ use std::{
|
||||
mpsc,
|
||||
},
|
||||
thread,
|
||||
time::{Duration, Instant},
|
||||
time::{Duration, Instant, SystemTime},
|
||||
};
|
||||
|
||||
use fancy_regex::Regex;
|
||||
@@ -18,7 +18,7 @@ use sequoia_openpgp::{
|
||||
Cert, Packet, armor,
|
||||
crypto::Password,
|
||||
packet::{
|
||||
Key,
|
||||
Key, UserID,
|
||||
key::{Key4, PrimaryRole, SecretParts},
|
||||
prelude::SignatureBuilder,
|
||||
},
|
||||
@@ -40,6 +40,7 @@ pub struct Config {
|
||||
pub status_enabled: bool,
|
||||
pub stop_after: Option<NonZeroU64>,
|
||||
pub password: Option<Password>,
|
||||
pub userids: Vec<UserID>,
|
||||
}
|
||||
|
||||
#[derive(Debug)]
|
||||
@@ -72,7 +73,7 @@ impl Fingerprunk {
|
||||
pub fn run(mut self) -> anyhow::Result<()> {
|
||||
self.started_instant = Instant::now();
|
||||
|
||||
let (sender, receiver) = mpsc::channel();
|
||||
let (sender, receiver) = mpsc::sync_channel(16);
|
||||
|
||||
{
|
||||
let sender = sender.clone();
|
||||
@@ -133,7 +134,7 @@ impl Fingerprunk {
|
||||
})
|
||||
}
|
||||
|
||||
fn worker_thread(&self, sender: mpsc::Sender<Message>) {
|
||||
fn worker_thread(&self, sender: mpsc::SyncSender<Message>) {
|
||||
let mut fingerprint_hex = String::with_capacity(20 * 2);
|
||||
|
||||
while !self.stop.load(Ordering::Relaxed) {
|
||||
@@ -143,9 +144,9 @@ impl Fingerprunk {
|
||||
write!(fingerprint_hex, "{:X}", key.fingerprint())
|
||||
.expect("should write into string without error");
|
||||
if self.check_fingerprint(&fingerprint_hex) {
|
||||
sender
|
||||
.send(Message::Key(Key::V4(key)))
|
||||
.expect("should be able to send key");
|
||||
// The channel might already be closed here if we're stopping.
|
||||
// That is fine, so we just ignore the error.
|
||||
let _ = sender.send(Message::Key(Key::V4(key)));
|
||||
}
|
||||
self.counter_tried.fetch_add(1, Ordering::Relaxed);
|
||||
}
|
||||
@@ -160,21 +161,19 @@ impl Fingerprunk {
|
||||
}
|
||||
|
||||
fn key_to_cert(&self, key: &SecretKey) -> anyhow::Result<Cert> {
|
||||
let sig = SignatureBuilder::new(SignatureType::DirectKey)
|
||||
.set_hash_algo(HashAlgorithm::SHA512)
|
||||
.set_preferred_hash_algorithms(vec![HashAlgorithm::SHA512, HashAlgorithm::SHA256])?
|
||||
.set_preferred_symmetric_algorithms(vec![
|
||||
SymmetricAlgorithm::AES256,
|
||||
SymmetricAlgorithm::AES128,
|
||||
])?;
|
||||
let creation_time = SystemTime::now();
|
||||
|
||||
let mut signer = key
|
||||
.clone()
|
||||
.into_keypair()
|
||||
.expect("key should have a secret");
|
||||
let sig = sig.sign_direct_key(&mut signer, key.parts_as_public())?;
|
||||
|
||||
let secret_key_packet = Packet::SecretKey({
|
||||
// Sign keypair
|
||||
let key_sig = create_sig_builder(SignatureType::DirectKey, creation_time)?
|
||||
.sign_direct_key(&mut signer, key.parts_as_public())?;
|
||||
|
||||
// Create certificate
|
||||
let mut cert = Cert::try_from(Packet::SecretKey({
|
||||
let mut key = key.clone();
|
||||
if let Some(ref password) = self.config.password {
|
||||
let (k, mut secret) = key.take_secret();
|
||||
@@ -182,9 +181,27 @@ impl Fingerprunk {
|
||||
key = k.add_secret(secret).0;
|
||||
}
|
||||
key
|
||||
});
|
||||
}))?;
|
||||
|
||||
Cert::try_from(vec![secret_key_packet, Packet::from(sig)])
|
||||
let mut packets = vec![Packet::from(key_sig)];
|
||||
|
||||
// Sign user IDs
|
||||
let mut next_is_primary = true;
|
||||
for user_id in self.config.userids.iter().cloned() {
|
||||
let mut sig_builder =
|
||||
create_sig_builder(SignatureType::PositiveCertification, creation_time)?;
|
||||
if next_is_primary {
|
||||
sig_builder = sig_builder.set_primary_userid(true)?;
|
||||
next_is_primary = false;
|
||||
}
|
||||
let sig = user_id.bind(&mut signer, &cert, sig_builder)?;
|
||||
|
||||
packets.push(user_id.into());
|
||||
packets.push(sig.into());
|
||||
}
|
||||
|
||||
cert = cert.insert_packets(packets)?.0;
|
||||
Ok(cert)
|
||||
}
|
||||
|
||||
fn serialize_cert(&self, cert: Cert, to: impl io::Write) -> anyhow::Result<()> {
|
||||
@@ -256,3 +273,17 @@ impl Fingerprunk {
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
fn create_sig_builder(
|
||||
typ: SignatureType,
|
||||
creation_time: SystemTime,
|
||||
) -> Result<SignatureBuilder, anyhow::Error> {
|
||||
SignatureBuilder::new(typ)
|
||||
.set_signature_creation_time(creation_time)?
|
||||
.set_hash_algo(HashAlgorithm::SHA512)
|
||||
.set_preferred_hash_algorithms(vec![HashAlgorithm::SHA512, HashAlgorithm::SHA256])?
|
||||
.set_preferred_symmetric_algorithms(vec![
|
||||
SymmetricAlgorithm::AES256,
|
||||
SymmetricAlgorithm::AES128,
|
||||
])
|
||||
}
|
||||
|
||||
+21
-1
@@ -7,6 +7,7 @@ use anyhow::{Context as AnyhowContext, anyhow};
|
||||
use clap::{ArgAction, Parser, ValueEnum};
|
||||
use fancy_regex::Regex;
|
||||
use fingerprunk::Fingerprunk;
|
||||
use sequoia_openpgp::packet::UserID;
|
||||
|
||||
#[derive(Parser, Debug)]
|
||||
#[command(version, about, long_about = None)]
|
||||
@@ -33,12 +34,22 @@ struct Args {
|
||||
#[arg(long)]
|
||||
stop_after: Option<NonZeroU64>,
|
||||
|
||||
/// Prompt for a password and use it to encrypt found keys.
|
||||
/// Prompt for a password and use it to encrypt matching keys.
|
||||
///
|
||||
/// By default, found keys are printed to stdout unencrypted. Use this if you actually plan to
|
||||
/// use generated keys.
|
||||
#[arg(short, long, action = ArgAction::SetTrue)]
|
||||
password: bool,
|
||||
|
||||
/// Add the given user ID to matching keys.
|
||||
#[arg(short, long = "userid")]
|
||||
userid: Vec<UserID>,
|
||||
|
||||
/// Explicitly do not add user IDs to matching keys.
|
||||
///
|
||||
/// Disables the warning about importing keys without user IDs into GnuPG.
|
||||
#[arg(long, conflicts_with = "userid", action = ArgAction::SetTrue)]
|
||||
no_userid: bool,
|
||||
}
|
||||
|
||||
#[derive(ValueEnum, Clone, Copy, Debug, Default)]
|
||||
@@ -62,6 +73,14 @@ impl StatusEnabled {
|
||||
fn main() -> anyhow::Result<()> {
|
||||
let args = Args::parse();
|
||||
|
||||
if !args.no_userid && args.userid.is_empty() {
|
||||
eprintln!(
|
||||
"WARNING: No user ID was provided.\n\
|
||||
You may experience problems importing generated keys into GnuPG.\n\
|
||||
Use the --userid option to add a user ID.\n"
|
||||
)
|
||||
}
|
||||
|
||||
let password = if args.password {
|
||||
let password = rpassword::prompt_password(
|
||||
"Enter password for encrypting found keys (leave empty for no encryption): ",
|
||||
@@ -87,6 +106,7 @@ fn main() -> anyhow::Result<()> {
|
||||
status_enabled: args.status.evaluate(),
|
||||
stop_after: args.stop_after,
|
||||
password,
|
||||
userids: args.userid,
|
||||
};
|
||||
|
||||
Fingerprunk::new_from_config(config).run()?;
|
||||
|
||||
Reference in New Issue
Block a user