[关闭]
@jzp113 2017-07-28T08:52:03.000000Z 字数 2507 阅读 1128

吉刻api加密分析

api 安装逆向

1.获取栏目略

2.获取文章
{"type":1,"chnlid":"ff80b5b5576f937501576fa7d0130000","newid":"2465668"}

替换栏目值,然后MD5上述字符串(大写)。
加密字符串,代码案例给出
请求地址:http://app.chinajilin.com.cn/App/mobile/api
请求内容:

  1. {
  2. "body": "z\/L84RA1\/EP7fMmAja7zqBs0Lr+H7pfD5+Ht4pmy+rSBbK84ypFqqoRUUdla SZxc697DIVd7tIrV5m4cXW8WUHvN6krb84SQg55OT+dswi8=",
  3. "header": {
  4. "length": "72",
  5. "md5": "44AB67E805202CE4F9A126881E5D7940",
  6. "num": "AE1002",
  7. "token": "71E61F81A057493F96CBFCDF7DFF8532",
  8. "cc": "1",
  9. "encrypt": "true",
  10. "version": "2.0.0"
  11. }
  12. }

在此输入正文

  1. <?php
  2. $key=bin2hex('u7ysDglRTDWu65CF_aWsDA==');
  3. $key = pack('H48',$key);//取48字节24个字符
  4. $iv='12345678';
  5. $msg = 'z\/L84RA1\/EP7fMmAja7zqBs0Lr+H7pfD5+Ht4pmy+rSBbK84ypFqqoRUUdla SZxc697DIVd7tIrV5m4cXW8WUHvN6krb84SQg55OT+dswi8=';
  6. $des = new STD3Des(base64_encode($key),base64_encode($iv));//mode:cbc
  7. $rs1 = $des->decrypt($msg);
  8. echo 'md5:'.strtoupper(md5($rs1)) ;
  9. echo '加密:'.$des->encrypt($rs1);
  10. echo '解密:'.($rs1) ;
  11. class STD3Des {
  12. private $key = "";
  13. private $iv = "";
  14. private $mode = MCRYPT_MODE_CBC;
  15. /**
  16. * 构造,传递二个已经进行base64_encode的KEY与IV
  17. *
  18. * @param string $key
  19. * @param string $iv
  20. */
  21. function __construct($key, $iv = null) {
  22. if (empty($key)) {
  23. echo 'key is not valid';
  24. exit();
  25. }
  26. if ($iv == null) {
  27. $iv = $key;
  28. $this->mode = MCRYPT_MODE_ECB;
  29. }
  30. $this->key = $key;
  31. $this->iv = $iv;
  32. }
  33. /**
  34. * 加密
  35. * @param <type> $value
  36. * @return <type>
  37. */
  38. public function encrypt($value) {
  39. $td = mcrypt_module_open(MCRYPT_3DES, '', $this->mode, '');
  40. $iv = $this->mode == MCRYPT_MODE_CBC ? base64_decode($this->iv) : mcrypt_create_iv(mcrypt_enc_get_iv_size($td), MCRYPT_RAND);
  41. $value = $this->PaddingPKCS7($value);
  42. $key = base64_decode($this->key);
  43. mcrypt_generic_init($td, $key, $iv);
  44. $dec = mcrypt_generic($td, $value);
  45. $ret = base64_encode($dec);
  46. mcrypt_generic_deinit($td);
  47. mcrypt_module_close($td);
  48. return $ret;
  49. }
  50. /**
  51. * 解密
  52. * @param <type> $value
  53. * @return <type>
  54. */
  55. public function decrypt($value) {
  56. $td = mcrypt_module_open(MCRYPT_3DES, '', $this->mode, '');
  57. $iv = $this->mode == MCRYPT_MODE_CBC ? base64_decode($this->iv) : mcrypt_create_iv(mcrypt_enc_get_iv_size($td), MCRYPT_RAND);
  58. $key = base64_decode($this->key);
  59. mcrypt_generic_init($td, $key, $iv);
  60. $ret = trim(mdecrypt_generic($td, base64_decode($value)));
  61. $ret = $this->UnPaddingPKCS7($ret);
  62. mcrypt_generic_deinit($td);
  63. mcrypt_module_close($td);
  64. return $ret;
  65. }
  66. private function PaddingPKCS7($data) {
  67. $block_size = mcrypt_get_block_size('tripledes', $this->mode);
  68. $padding_char = $block_size - (strlen($data) % $block_size);
  69. $data .= str_repeat(chr($padding_char), $padding_char);
  70. return $data;
  71. }
  72. private function UnPaddingPKCS7($text) {
  73. $pad = ord($text{strlen($text) - 1});
  74. if ($pad > strlen($text)) {
  75. return false;
  76. }
  77. if (strspn($text, chr($pad), strlen($text) - $pad) != $pad) {
  78. return false;
  79. }
  80. return substr($text, 0, -1 * $pad);
  81. }
  82. }
添加新批注
在作者公开此批注前,只有你和作者可见。
回复批注