ITPUB

关于shell脚本如何加密,避免敏感信息泄露

关于shell脚本如何加密,避免敏感信息泄露

本文将介绍3种加密办法:

1、通过base64编码对shell脚本进行加密解密

2、通过OpenSSL对shell脚本进行加密解密

3、通过shc工具对shell脚本进行加密解密

为什么需要加密?

创建一个MySQL备份的shell脚本,这个脚本里面存在数据库账号root的明文密码,一旦脚本被泄露,将带来严重的安全风险。因此,我们需要采取措施来保护这些敏感信息。确保即使文件被访问,也无法轻易读取到其中的敏感数据。

[root@localhost ~]# vim  xunjian.sh
[root@localhost ~]# cat xunjian.sh 
#!/bin/bash
mysqldump -uroot -pMy12SQL -A>/tmp/all.sql

如何实现?

一、使用base64编码进行加密解密

base64 编码并不是真正的加密方式,而是一种编码格式,它主要用于将二进制数据转换为文本格式,以便在网络上传输或存储。尽管它不能提供强安全性,但对于简单的隐藏需求来说是足够了。

通过base64编码方式对脚本进行编码

[root@localhost ~]# base64 xunjian.sh  > xunjian_base64.txt

查看编码后的文件内容

[root@localhost ~]# cat xunjian_base64.txt
IyEvYmluL2Jhc2gKbXlzcWxkdW1wIC11cm9vdCAtcE15MTJTUUwgLUE+IC90bXAvYWxsLnNxbAo=

通过base64方式对编码文件进行解码

[root@localhost ~]# base64 -d xunjian_base64.txt 
#!/bin/bash
mysqldump -uroot -pMy12SQL -A>/tmp/all.sql

通过base64方式对编码文件进行解码并执行

[root@localhost ~]# base64 -d xunjian_base64.txt | bash
[root@localhost ~]# ll /tmp/all.sql 
-rw-r--r--1 root root 3.9MDec2322:01 all.sql

特别提示:

虽然 base64 编码可以简单地隐藏脚本内容,但它并不适合用于保护敏感信息,因为任何人只要知道这是 base64 编码的内容,就可以轻松解码出来。因此,对于更高级别的安全需求,推荐使用更强大的加密方法

二、使用OpenSSL工具进行加密解密

OpenSSL 提供了多种强大的加密算法和工具,可以用来保护 Shell 脚本中的敏感信息。下面我们将介绍如何使用 OpenSSL 的 AES-256-CBC 加密算法来加密和解密 Shell 脚本。

使用 OpenSSL 对xunjian.sh脚本进行加密,并保存加密后的文件为 xunjian.sh.enc。我们将同时创建一个包含密码的文件 password.txt,用于后续解密时提供密码

创建密码文件,并严格设置权限

为了安全地管理加密密码,建议创建一个单独的密码文件,并严格限制其访问权限。

[root@localhost ~]# echo "123456"> password.txt
[root@localhost ~]# chmod 600 password.txt

注意事项:

  • • 确保密码足够强壮,并妥善保管。
  • • 密码文件应与加密文件分开存储,以避免两者同时被盗取的风险。

使用OpenSSL进行加密

[root@localhost ~]# openssl aes-256-cbc -salt -pbkdf2 -in xunjian.sh -out xunjian.sh.enc -pass file:./password.txt

上述命令的各部分含义如下:

  • • aes-256-cbc:指定使用的加密算法为AES-256-CBC。
  • • -salt:添加随机盐值以增加安全性。
  • • -pbkdf2:使用PBKDF2密钥派生函数,这是推荐的安全实践。
  • • -in xunjian.sh:指定输入文件为xunjian.sh。
  • • -out xunjian.sh.enc:指定输出加密后的文件名为xunjian.sh.enc。
  • • -pass:指定密码短语提供方式,从文件 password.txt 中读取密码。

解密shell脚本

当需要解密该脚本时,使用如下命令:

[root@localhost ~]# openssl aes-256-cbc -d -pbkdf2 -in xunjian.sh.enc -pass file:./password.txt
#!/bin/bash
mysqldump -uroot -pMy12SQL -A>/tmp/all.sql

命令参数解释:

  • • -d:表示进行解密操作。
  • • 其他参数与加密命令相同。

解密shell脚本并执行

如果想要直接运行解密后的脚本而不保存到文件中,可以结合bash实现:

[root@localhost ~]# openssl aes-256-cbc -d -pbkdf2 -in xunjian.sh.enc -pass file:./password.txt | bash
[root@localhost ~]# ll /tmp/all.sql 
-rw-r--r--1 root root 3.9MDec2322:30 all.sql

关于Pass Phrase Options(密码短语选项)

OpenSSL 支持多种方式来提供加密和解密所需的密码短语(passphrase)。这使得我们可以根据具体的安全需求选择最合适的方式来管理密码。

  • • pass:password:直接在命令行中指定密码。这种方式最不安全,因为密码会显示在命令行历史记录和系统进程列表中。
  • • env:var:从环境变量中获取密码。需要注意的是,在某些操作系统上,其他用户可能能够查看进程的环境变量,因此这种方法也需要谨慎使用。
  • • file:pathname:从文件 pathname 的第一行读取密码。如果同一个文件路径被同时用作 -passin 和 -passout 参数,则第一行作为输入密码,第二行作为输出密码。这是较为安全的选择,因为它不会暴露在命令行历史记录或进程列表中。我们上面的例子就是使用这种方法。
  • • fd:number:从文件描述符读取密码。这可以用来通过管道传递数据,适用于需要动态提供密码的场景。
  • • stdin:从标准输入读取密码。这种方式会在命令执行时提示用户输入密码,适合交互式使用,但不适合自动化脚本。

三、使用SHC工具进行加密解密

shc是shell编译器(Shell Compiler)的缩写, 它可以对shell脚本进行编译和加密。它能够将shell脚本编译为可执行的二进制文件,其中包含了脚本的功能和逻辑,而不暴露源代码。shc在github托管地址:https://github.com/neurobin/shc/releases

shc工具安装

源码下载shc工具并编译安装

[root@localhost ~]# wget http://www.datsi.fi.upm.es/~frosal/sources/shc-3.8.9b.tgz
[root@localhost ~]# tar -zxvf shc-4.0.3.tar.gz 
[root@localhost ~]# cd shc-4.0.3
[root@localhost shc-4.0.3]#./configure
[root@localhost shc-4.0.3]# make
[root@localhost shc-4.0.3]# make install

shc工具使用帮助

下面是shc比较常用的参数说明,更多参数说明请参考man手册或官方文档。

参数
参数说明
-h
显示帮助信息并退出
-f
指定需要加密的shell脚本
-v
参数-v表示verbose模式,输出更详细的编译日志
-r
可以在相同操作系统的不同系统中执行,也就是放宽安全限制,生成可再分发的二进制文件
-o
输出文件名,也可以不指定
-f
指定shell脚本名称
-e
指定过期日期
-m
指定过期后的提示信息
-U
使二进制无法被追踪,默认不开启
-H
强化:额外的安全保护,默认不开启,它需要shell不支持参数

使用shc工具加密shell脚本

#加密shell脚本
[root@localhost ~]# shc -v -f xunjian.sh 
shc shll=bash
shc [-i]=-c
shc [-x]=exec'%s'"$@"
shc [-l]=
shc opts=
shc: cc   xunjian.sh.x.c -o xunjian.sh.x
shc: strip xunjian.sh.x
shc: chmod ug=rwx,o=rx xunjian.sh.x

#
加密完成后可以发现生成了两个文件
[root@localhost ~]# ll
......
-rw-------1 root root        56Dec2409:49 xunjian.sh
-rwxrwxr-x  1 root root     15312Dec2517:22 xunjian.sh.x
-rw-------1 root root     18023Dec2517:22 xunjian.sh.x.c

#
我们使用file命令查看文件的类型
[root@localhost ~]# file xunjian.sh
xunjian.sh:Bourne-Again shell script, ASCII text executable
[root@localhost ~]# file xunjian.sh.x
xunjian.sh.x: ELF 64-bit LSB executable, x86-64, version 1(SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2,BuildID[sha1]=511a7ac43e893dff1a52999c8ba3e4cc236bc554,for GNU/Linux3.2.0, stripped
[root@localhost ~]# file xunjian.sh.x.c 
xunjian.sh.x.c: C source, ASCII text

正如上面输出的一样,加密完成后生成了两个文件:

  • • xunjian.sh是原始的未加密shell脚本(执行加密生成新的可执行二进制文件后便可以删除了)
  • • xunjian.sh.x是加密过后的可执行的二进制文件。
  • • xunjian.sh.x.c是xunjian.sh文件的C源代码,也就是说编译该C源代码文件可以创建上面加密的xunjian.sh.x文件,(可以删除)

执行加密后的shell脚本文件

[root@localhost ~]#./xunjian.sh.x 

#
可以发现加密后的脚本文件能够正常执行
[root@localhost ~]# ll -h /tmp/all.sql 
-rw-------1 root root 3.8MDec2517:22/tmp/all.sql

设定加密后的Shell脚本过期时间及过期提示信息

shc还可以通过-e参数设定加密脚本有效执行期限,编译生成的可执行二进制文件在过了这个有效时间后,便不能执行,将收到错误消息。到期日期以dd/mm/yyyy 格式指定。还可以通过-m参数指定提示信息

#创建带有过期时间的加密脚本并给与过期提示信息
[root@localhost ~]# shc -e 20/12/2024-m "the script has expired, please contact your provierder [email protected]"-v -f xunjian.sh
shc shll=bash
shc [-i]=-c
shc [-x]=exec'%s'"$@"
shc [-l]=
shc opts=
shc: cc   xunjian.sh.x.c -o xunjian.sh.x
shc: strip xunjian.sh.x
shc: chmod ug=rwx,o=rx xunjian.sh.x

[root@localhost ~]# ll xunjian.sh*
-rw-------1 root root  56Dec1821:08 xunjian.sh
-rwxrwxr-x 1 root root 15KDec2521:20 xunjian.sh.x
-rw-r--r--1 root root 18KDec2521:20 xunjian.sh.x.c

#
如果尝试执行已过期的加密二进制文件,会打印设置的过期提示信息
[root@localhost ~]#./xunjian.sh.x 
./xunjian.sh.x: has expired!
the script has expired, please contact your provierder 1234@foxmail.com

如何解密SHc加密的.sh.x文件?

加密完成了,那应该如何解密SHc加密的*.sh.x文件,这便要用到UnSHc。但需要说明的是:在shc 4.0.3中,纳入了许多结构性更改,现在shc利用了Linux内核本身提供的各种安全机制。因此,如果使用的是新版shc,当前版本的UnSHc几乎不可能提取出原始的Shell脚本。注意:这只是现在不能,不代表以后不能,如果你能读懂源代码,对UnSHc加密脚本做加工,那也没什么不可能

工具下载地址:https://github.com/yanncam/UnSHc/blob/master/latest/unshc.sh,其实就是一个shell脚本。

#下载后授权并查看帮助如何使用
[root@localhost ~]# chmod +x unshc.sh 
[root@localhost ~]#./unshc.sh -h
 _   _       _____ _   _      
||||/  ___||||
||||_ __ \ `--.| |_| | ___ 
| | | | '_ \ `--. \  _  |/ __|
||_||||/\__//|||(__ 
 \___/|_||_\____/\_||_/\___|

---UnSHc-The shc decrypter.
---Version:0.8
------------------------------
UnSHcis used to decrypt script encrypted withSHc
Original idea fromLuizOctavioDuarte(LOD)
Updatedand modernized byYann CAM
-SHc:[http://www.datsi.fi.upm.es/~frosal/]
-UnSHc:[https://www.asafety.fr/unshc-the-shc-decrypter/]
------------------------------

[*]Usage:./unshc.sh [OPTIONS]<file.sh.x>
-h |--help                          :printthis help message
-a OFFSET |--arc4 OFFSET            : specify the arc4() offset arbitrarily (without 0x prefix)
-d DUMPFILE |--dumpfile DUMPFILE    : provide an objectdump file (objdump -D script.sh.x > DUMPFILE)
-s STRFILE |--stringfile STRFILE    : provide a stringdump file (objdump -s script.sh.x > STRFILE)
-o OUTFILE |--outputfile OUTFILE    : indicate the output file name

[*] e.g :
./unshc.sh script.sh.x
./unshc.sh script.sh.x -o script_decrypted.sh
./unshc.sh script.sh.x -a 400f9b
./unshc.sh script.sh.x -d /tmp/dumpfile -s /tmp/strfile
./unshc.sh script.sh.x -a 400f9b-d /tmp/dumpfile -s /tmp/strfile -o script_decrypted.sh

对shc-4.0.3版本加密的二进制文件做解密确认解密失败,无法解密

[root@localhost ~]#./unshc.sh  xunjian.sh.x
 _   _       _____ _   _      
||||/  ___||||
||||_ __ \ `--.| |_| | ___ 
| | | | '_ \ `--. \  _  |/ __|
||_||||/\__//|||(__ 
 \___/|_||_\____/\_||_/\___|

---UnSHc-The shc decrypter.
---Version:0.8
------------------------------
UnSHcis used to decrypt script encrypted withSHc
Original idea fromLuizOctavioDuarte(LOD)
Updatedand modernized byYann CAM
-SHc:[http://www.datsi.fi.upm.es/~frosal/]
-UnSHc:[https://www.asafety.fr/unshc-the-shc-decrypter/]
------------------------------

[*]Input file name to decrypt [xunjian.sh.x]
[-]Unable to define arc4() call address...

对shc-3.8.9b版本加密的二进制文件做解密确认解密成功

[root@localhost ~]#./unshc.sh xunjian.sh.x -o /tmp/script_decrypted.sh
 _   _       _____ _   _      
||||/  ___||||
||||_ __ \ `--.| |_| | ___ 
| | | | '_ \ `--. \  _  |/ __|
||_||||/\__//|||(__ 
 \___/|_||_\____/\_||_/\___|

---UnSHc-The shc decrypter.
---Version:0.8
------------------------------
UnSHcis used to decrypt script encrypted withSHc
Original idea fromLuizOctavioDuarte(LOD)
Updatedand modernized byYann CAM
-SHc:[http://www.datsi.fi.upm.es/~frosal/]
-UnSHc:[https://www.asafety.fr/unshc-the-shc-decrypter/]
------------------------------

[*]Input file name to decrypt [xunjian.sh.x]
[+]Output file name specified [/tmp/script_decrypted.sh]
[+] ARC4 address call candidate :[0x40142a]
[*]Extracting each args address and size for the 14 arc4() calls with address [0x40142a]...
[0]Workingwithvar address at offset [0x404372](0x2a bytes)
[1]Workingwithvar address at offset [0x404120](0x1 bytes)
[2]Workingwithvar address at offset [0x404189](0xa bytes)
[3]Workingwithvar address at offset [0x40433c](0x3 bytes)
[4]Workingwithvar address at offset [0x4043a4](0xf bytes)
[5]Workingwithvar address at offset [0x4043b4](0x1 bytes)
[6]Workingwithvar address at offset [0x404357](0x16 bytes)
[7]Workingwithvar address at offset [0x404321](0x16 bytes)
[8]Workingwithvar address at offset [0x404199](0x13 bytes)
[9]Workingwithvar address at offset [0x404121](0x1 bytes)
[10]Workingwithvar address at offset [0x40433f](0x1 bytes)
[11]Workingwithvar address at offset [0x40412c](0x39 bytes)
[12]Workingwithvar address at offset [0x404174](0x13 bytes)
[13]Workingwithvar address at offset [0x404343](0x13 bytes)
[*]Extracting password...
[+] PWD address found :[0x4041ee]
[+] PWD size found :[0x100]
[*]Executing[/tmp/Kocrob] to decrypt [xunjian.sh.x]
[*]Retrieving initial source code in[/tmp/script_decrypted.sh]
[*]Alldone!

#
查看解密后文件确认能正常看到文件内容
[root@localhost ~]# cat /tmp/script_decrypted.sh 
#!/bin/bash
mysqldump -uroot -pMy12SQL -A>/tmp/all.sql

总结

不同加密方法的优缺点

1、Base64 编码

  • • 优点:简单易用,适合简单的隐藏需求。
  • • 缺点:不是真正的加密方式,任何人都可以轻松解码。不适合保护敏感信息。

2、OpenSSL 加密

  • • 优点:提供强加密算法(如 AES-256-CBC),支持多种安全特性(如加盐、PBKDF2),适合保护敏感信息。
  • • 缺点:相对复杂,需要管理密码文件和依赖项。

3、shc 工具

  • • 优点:可以编译 Shell 脚本为二进制文件,防止直接查看脚本内容。
  • • 缺点:并不是真正的编译器,生成的二进制文件仍然依赖于原始 Shell 解释器;安全性有限,有经验的用户可以通过反向工程恢复原始脚本。

最佳实践

  • • 选择合适的加密方法:根据具体的敏感程度和应用场景选择最合适的加密方法。对于高敏感度的信息,推荐使用 OpenSSL 提供的强加密算法。
  • • 安全管理密码:无论是使用 OpenSSL 还是 shc,都应确保密码的安全管理,避免泄露。可以考虑使用环境变量或单独的密码文件,并严格限制其访问权限。
  • • 定期审查和更新:定期检查和更新密码及权限设置,以应对潜在的安全威胁。确保所有依赖库和环境变量在目标机器上正确配置。
  • • 备份和删除原始文件:在加密前,请确保有原始文件的备份。一旦加密过程完成,原始文件最好删除或妥善保管,以免泄露未加密的内容。
  • • 配置文件权限控制:严格限制敏感配置文件的访问权限,确保只有授权用户可以读取。

Image