Saya bekerja di PowerShell dan saya memiliki kode yang berhasil mengubah kata sandi yang dimasukkan pengguna menjadi teks biasa:
$SecurePassword = Read-Host -AsSecureString "Enter password" | convertfrom-securestring | out-file C:\Users\tmarsh\Documents\securePassword.txt
Saya telah mencoba beberapa cara untuk mengubahnya kembali, tetapi tidak satupun dari mereka tampaknya berfungsi dengan baik. Baru-baru ini, saya sudah mencoba dengan yang berikut:
$PlainPassword = Get-Content C:\Users\tmarsh\Documents\securePassword.txt
#convert the SecureString object to plain text using PtrToString and SecureStringToBSTR
$BSTR = [System.Runtime.InteropServices.Marshal]::SecureStringToBSTR($PlainPassword)
$PlainPassword = [System.Runtime.InteropServices.Marshal]::PtrToStringAuto($BSTR)
[Runtime.InteropServices.Marshal]::ZeroFreeBSTR($BSTR) #this is an important step to keep things secure
Ini memberi saya kesalahan juga.
Cannot convert argument "s", with value: "01000000d08c9ddf0115d1118c7a00c04fc297eb0100000026a5b6067d53fd43801a9ef3f8ef9e43000000000200000000000366000
0c0000000100000008118fdea02bfb57d0dda41f9748a05f10000000004800000a000000010000000c50f5093f3b87fbf9ee57cbd17267e0a10000000833d1d712cef01497872a3457bc8
bc271400000038c731cb8c47219399e4265515e9569438d8e8ed", for "SecureStringToBSTR" to type "System.Security.SecureString": "Cannot convert the "01000000
d08c9ddf0115d1118c7a00c04fc297eb0100000026a5b6067d53fd43801a9ef3f8ef9e430000000002000000000003660000c0000000100000008118fdea02bfb57d0dda41f9748a05f10
000000004800000a000000010000000c50f5093f3b87fbf9ee57cbd17267e0a10000000833d1d712cef01497872a3457bc8bc271400000038c731cb8c47219399e4265515e9569438d8e8
ed" value of type "System.String" to type "System.Security.SecureString"."
At C:\Users\tmarsh\Documents\Scripts\Local Admin Script\PlainTextConverter1.ps1:14 char:1
+ $BSTR = [System.Runtime.InteropServices.Marshal]::SecureStringToBSTR($PlainPassw ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : NotSpecified: (:) [], MethodException
+ FullyQualifiedErrorId : MethodArgumentConversionInvalidCastArgument
Cannot find an overload for "PtrToStringAuto" and the argument count: "1".
At C:\Users\tmarsh\Documents\Scripts\Local Admin Script\PlainTextConverter1.ps1:15 char:1
+ $PlainPassword = [System.Runtime.InteropServices.Marshal]::PtrToStringAuto($BSTR ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : NotSpecified: (:) [], MethodException
+ FullyQualifiedErrorId : MethodCountCouldNotFindBest
Cannot convert argument "s", with value: "", for "ZeroFreeBSTR" to type "System.IntPtr": "Cannot convert null to type "System.IntPtr"."
At C:\Users\tmarsh\Documents\Scripts\Local Admin Script\PlainTextConverter1.ps1:16 char:1
+ [Runtime.InteropServices.Marshal]::ZeroFreeBSTR($BSTR) #this is an important ste ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : NotSpecified: (:) [], MethodException
+ FullyQualifiedErrorId : MethodArgumentConversionInvalidCastArgument
Password is: 01000000d08c9ddf0115d1118c7a00c04fc297eb0100000026a5b6067d53fd43801a9ef3f8ef9e430000000002000000000003660000c0000000100000008118fdea02bfb57d0dda41f97
48a05f10000000004800000a000000010000000c50f5093f3b87fbf9ee57cbd17267e0a10000000833d1d712cef01497872a3457bc8bc271400000038c731cb8c47219399e4265515e9569
438d8e8ed
Adakah yang tahu cara yang akan berhasil untuk ini?
powershell
securestring
tmarsh
sumber
sumber
[Runtime.InteropServices.Marshal]::ZeroFreeBSTR($BSTR)
.$BSTR = $null
?$null
, karena di sini kita berurusan dengan objek yang tidak dikelola. Anda tidak akan langsung mendapatkan error, tetapi saya rasa Anda mungkin akan mengalami masalah seiring berjalannya waktu.ZeroFreeBSTR()
, seperti yang dinyatakan, penggunaan dariPtrToStringAuto()
selalu cacat secara konseptual, dan - sekarang PowerShell adalah lintas platform - gagal pada platform mirip Unix. Seharusnya selaluPtrToStringBSTR()
- lihat jawaban ini .Anda juga dapat menggunakan PSCredential.GetNetworkCredential ():
$SecurePassword = Get-Content C:\Users\tmarsh\Documents\securePassword.txt | ConvertTo-SecureString $UnsecurePassword = (New-Object PSCredential "user",$SecurePassword).GetNetworkCredential().Password
sumber
System.Management.Automation.PSCredential
di versi PS yang lebih lama ketika nama tipe pendek tidak dikenali.[PSCredential]::new(0, $SecurePassword).GetNetworkCredential().Password
[System.Net.NetworkCredential]::new("", $SecurePassword).Password
Cara termudah untuk mengubahnya kembali di PowerShell
[System.Net.NetworkCredential]::new("", $SecurePassword).Password
sumber
SecureString
ini diperkenalkan di .Net Framework 4.0. Pada PowerShell v2 saya mencoba(New-Object -TypeName System.Net.NetworkCredential -ArgumentList "u",$SecureString).Password
tetapi sayangnyaSecureString
secara diam-diam diubah menjadiString
. Panggilan tampaknya berhasil, tetapiPassword
properti kemudian menjadi nilai literal "System.Security.SecureString". Hati-hati.Di PS 7, Anda dapat menggunakan
ConvertFrom-SecureString
dan-AsPlainText
:$UnsecurePassword = ConvertFrom-SecureString -SecureString $SecurePassword -AsPlainText
https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.security/ConvertFrom-SecureString?view=powershell-7#parameters
ConvertFrom-SecureString [-SecureString] <SecureString> [-AsPlainText] [<CommonParameters>]
sumber