Ecosyste.ms: Awesome
An open API service indexing awesome lists of open source software.
https://github.com/HoLLy-HaCKeR/KeePassHax
A tool to extract a KeePass master password from memory
https://github.com/HoLLy-HaCKeR/KeePassHax
keepass keepass-related password-manager security
Last synced: 2 months ago
JSON representation
A tool to extract a KeePass master password from memory
- Host: GitHub
- URL: https://github.com/HoLLy-HaCKeR/KeePassHax
- Owner: holly-hacker
- License: mit
- Created: 2018-05-08T15:30:24.000Z (over 6 years ago)
- Default Branch: master
- Last Pushed: 2020-12-11T21:54:57.000Z (about 4 years ago)
- Last Synced: 2024-08-04T01:16:28.593Z (6 months ago)
- Topics: keepass, keepass-related, password-manager, security
- Language: C#
- Size: 16.6 KB
- Stars: 76
- Watchers: 8
- Forks: 15
- Open Issues: 0
-
Metadata Files:
- Readme: README.md
- License: LICENSE
Awesome Lists containing this project
- awesome-keepass - KeePassHax - Extracts master password from a KeePass 2.x database, (Security / Other clients)
README
# KeePassHax
KeePassHax is a managed DLL that, when injected into the KeePass process, will extract all data that makes up the
CompositeKey used to decrypt the password database. This data (along with the database) could be transmitted to some
server running in the cloud to then be decrypted and abused in all kinds of fun ways.Inspired by [KeeFarce](https://github.com/denandz/KeeFarce), but better ;)
## Building
Compile it with Visual Studio 2017 or higher ¯\\\_(ツ)\_/¯## Usage
If you already have a managed DLL injector (like
[this one](https://www.codeproject.com/articles/607352/injecting-net-assemblies-into-unmanaged-processes)), you can
build the KeePassHax project and inject the resulting DLL into the KeePass project. You do not need administrator
permissions for this, so it can be ran from the context of any application.Alternatively, use the KeePassHax.Injector project to build a binary that, when run, injects itself into KeePass
process.You can see it in action in [this video](https://youtu.be/J663mUBIzE0).
## Disclaimer
You probably could have guessed this, but I don't take responsibility for what you do with this. Please don't use this
to actually steal passwords. This is merely a proof-of-concept to remind people to not run untrusted programs.## License
This code is licensed under the MIT license. I will always appreciate a link back to this repository :)