windows 在 Python 中使用 DPAPI?

声明:本页面是StackOverFlow热门问题的中英对照翻译,遵循CC BY-SA 4.0协议,如果您需要使用它,必须同样遵循CC BY-SA许可,注明原文地址和作者信息,同时你必须将它归于原作者(不是我):StackOverFlow 原文地址: http://stackoverflow.com/questions/463832/
Warning: these are provided under cc-by-sa 4.0 license. You are free to use/share it, But you must attribute it to the original authors (not me): StackOverFlow

提示:将鼠标放在中文语句上可以显示对应的英文。显示中英文
时间:2020-09-15 11:51:42  来源:igfitidea点击:

Using DPAPI with Python?

pythonwindowssecurityencryptiondpapi

提问by Wayne Koorts

Is there a way to use the DPAPI (Data Protection Application Programming Interface) on Windows XP with Python?

有没有办法在带有 Python 的 Windows XP 上使用 DPAPI(数据保护应用程序编程接口)?

I would prefer to use an existing module if there is one that can do it. Unfortunately I haven't been able to find a way with Google or Stack Overflow.

如果有一个可以做到的模块,我更愿意使用现有模块。不幸的是,我无法通过 Google 或 Stack Overflow 找到方法。

EDIT:I've taken the example code pointed to by "dF" and tweaked it into a standalone library which can be simply used at a high level to crypt and decrypt using DPAPI in user mode. Simply call dpapi.cryptData(text_to_encrypt) which returns an encrypted string, or the reverse decryptData(encrypted_data_string), which returns the plain text. Here's the library:

编辑:我已经采用了“dF”指向的示例代码并将其调整为一个独立的库,该库可以简单地在高级别的使用,以在用户模式下使用 DPAPI 进行加密和解密。只需调用 dpapi.cryptData(text_to_encrypt) 返回加密字符串,或反向解密数据(encrypted_data_string),返回纯文本。这是图书馆:

# DPAPI access library
# This file uses code originally created by Crusher Joe:
# http://article.gmane.org/gmane.comp.python.ctypes/420
#

from ctypes import *
from ctypes.wintypes import DWORD

LocalFree = windll.kernel32.LocalFree
memcpy = cdll.msvcrt.memcpy
CryptProtectData = windll.crypt32.CryptProtectData
CryptUnprotectData = windll.crypt32.CryptUnprotectData
CRYPTPROTECT_UI_FORBIDDEN = 0x01
extraEntropy = "cl;ad13 ##代码##al;323kjd #(adl;k$#ajsd"

class DATA_BLOB(Structure):
    _fields_ = [("cbData", DWORD), ("pbData", POINTER(c_char))]

def getData(blobOut):
    cbData = int(blobOut.cbData)
    pbData = blobOut.pbData
    buffer = c_buffer(cbData)
    memcpy(buffer, pbData, cbData)
    LocalFree(pbData);
    return buffer.raw

def Win32CryptProtectData(plainText, entropy):
    bufferIn = c_buffer(plainText, len(plainText))
    blobIn = DATA_BLOB(len(plainText), bufferIn)
    bufferEntropy = c_buffer(entropy, len(entropy))
    blobEntropy = DATA_BLOB(len(entropy), bufferEntropy)
    blobOut = DATA_BLOB()

    if CryptProtectData(byref(blobIn), u"python_data", byref(blobEntropy),
                       None, None, CRYPTPROTECT_UI_FORBIDDEN, byref(blobOut)):
        return getData(blobOut)
    else:
        return ""

def Win32CryptUnprotectData(cipherText, entropy):
    bufferIn = c_buffer(cipherText, len(cipherText))
    blobIn = DATA_BLOB(len(cipherText), bufferIn)
    bufferEntropy = c_buffer(entropy, len(entropy))
    blobEntropy = DATA_BLOB(len(entropy), bufferEntropy)
    blobOut = DATA_BLOB()
    if CryptUnprotectData(byref(blobIn), None, byref(blobEntropy), None, None,
                              CRYPTPROTECT_UI_FORBIDDEN, byref(blobOut)):
        return getData(blobOut)
    else:
        return ""

def cryptData(text):
    return Win32CryptProtectData(text, extraEntropy)

def decryptData(cipher_text):
    return Win32CryptUnprotectData(cipher_text, extraEntropy)

采纳答案by dF.

I have been using CryptProtectDataand CryptUnprotectDatathrough ctypes, with the code from

我一直在使用CryptProtectDataCryptUnprotectData通过 ctypes,代码来自

http://article.gmane.org/gmane.comp.python.ctypes/420

http://article.gmane.org/gmane.comp.python.ctypes/420

and it has been working well.

它一直运行良好。

回答by Jason R. Coombs

Also, pywin32 implements CryptProtectData and CryptUnprotectData in the win32crypt module.

此外,pywin32 在 win32crypt 模块中实现了 CryptProtectData 和 CryptUnprotectData。

回答by Alan

The easiest way would be to use Iron Python.

最简单的方法是使用Iron Python