关于shell脚本如何加密,避免敏感信息泄露
关于shell脚本如何加密,避免敏感信息泄露
本文将介绍3种加密办法:
1、通过base64编码对shell脚本进行加密解密
2、通过OpenSSL对shell脚本进行加密解密
3、通过shc工具对shell脚本进行加密解密
为什么需要加密?
创建一个MySQL备份的shell脚本,这个脚本里面存在数据库账号root的明文密码,一旦脚本被泄露,将带来严重的安全风险。因此,我们需要采取措施来保护这些敏感信息。确保即使文件被访问,也无法轻易读取到其中的敏感数据。
[root@localhost ~]# vim xunjian.sh
[root@localhost ~]# cat xunjian.sh
#!/bin/bash
mysqldump -uroot -pMy12SQL -A>/tmp/all.sql如何实现?
一、使用base64编码进行加密解密
base64 编码并不是真正的加密方式,而是一种编码格式,它主要用于将二进制数据转换为文本格式,以便在网络上传输或存储。尽管它不能提供强安全性,但对于简单的隐藏需求来说是足够了。
通过base64编码方式对脚本进行编码
[root@localhost ~]# base64 xunjian.sh > xunjian_base64.txt查看编码后的文件内容
[root@localhost ~]# cat xunjian_base64.txt
IyEvYmluL2Jhc2gKbXlzcWxkdW1wIC11cm9vdCAtcE15MTJTUUwgLUE+IC90bXAvYWxsLnNxbAo=通过base64方式对编码文件进行解码
[root@localhost ~]# base64 -d xunjian_base64.txt
#!/bin/bash
mysqldump -uroot -pMy12SQL -A>/tmp/all.sql通过base64方式对编码文件进行解码并执行
[root@localhost ~]# base64 -d xunjian_base64.txt | bash
[root@localhost ~]# ll /tmp/all.sql
-rw-r--r--1 root root 3.9MDec2322:01 all.sql特别提示:
虽然 base64 编码可以简单地隐藏脚本内容,但它并不适合用于保护敏感信息,因为任何人只要知道这是 base64 编码的内容,就可以轻松解码出来。因此,对于更高级别的安全需求,推荐使用更强大的加密方法
二、使用OpenSSL工具进行加密解密
OpenSSL 提供了多种强大的加密算法和工具,可以用来保护 Shell 脚本中的敏感信息。下面我们将介绍如何使用 OpenSSL 的 AES-256-CBC 加密算法来加密和解密 Shell 脚本。
使用 OpenSSL 对xunjian.sh脚本进行加密,并保存加密后的文件为 xunjian.sh.enc。我们将同时创建一个包含密码的文件 password.txt,用于后续解密时提供密码
创建密码文件,并严格设置权限
为了安全地管理加密密码,建议创建一个单独的密码文件,并严格限制其访问权限。
[root@localhost ~]# echo "123456"> password.txt
[root@localhost ~]# chmod 600 password.txt注意事项:
• 确保密码足够强壮,并妥善保管。 • 密码文件应与加密文件分开存储,以避免两者同时被盗取的风险。
使用OpenSSL进行加密
[root@localhost ~]# openssl aes-256-cbc -salt -pbkdf2 -in xunjian.sh -out xunjian.sh.enc -pass file:./password.txt上述命令的各部分含义如下:
• aes-256-cbc:指定使用的加密算法为AES-256-CBC。• -salt:添加随机盐值以增加安全性。• -pbkdf2:使用PBKDF2密钥派生函数,这是推荐的安全实践。• -in xunjian.sh:指定输入文件为xunjian.sh。• -out xunjian.sh.enc:指定输出加密后的文件名为xunjian.sh.enc。• -pass:指定密码短语提供方式,从文件 password.txt 中读取密码。
解密shell脚本
当需要解密该脚本时,使用如下命令:
[root@localhost ~]# openssl aes-256-cbc -d -pbkdf2 -in xunjian.sh.enc -pass file:./password.txt
#!/bin/bash
mysqldump -uroot -pMy12SQL -A>/tmp/all.sql命令参数解释:
• -d:表示进行解密操作。 • 其他参数与加密命令相同。
解密shell脚本并执行
如果想要直接运行解密后的脚本而不保存到文件中,可以结合bash实现:
[root@localhost ~]# openssl aes-256-cbc -d -pbkdf2 -in xunjian.sh.enc -pass file:./password.txt | bash
[root@localhost ~]# ll /tmp/all.sql
-rw-r--r--1 root root 3.9MDec2322:30 all.sql关于Pass Phrase Options(密码短语选项)
OpenSSL 支持多种方式来提供加密和解密所需的密码短语(passphrase)。这使得我们可以根据具体的安全需求选择最合适的方式来管理密码。
• pass:password:直接在命令行中指定密码。这种方式最不安全,因为密码会显示在命令行历史记录和系统进程列表中。 • env:var:从环境变量中获取密码。需要注意的是,在某些操作系统上,其他用户可能能够查看进程的环境变量,因此这种方法也需要谨慎使用。 • file:pathname:从文件 pathname 的第一行读取密码。如果同一个文件路径被同时用作 -passin 和 -passout 参数,则第一行作为输入密码,第二行作为输出密码。这是较为安全的选择,因为它不会暴露在命令行历史记录或进程列表中。我们上面的例子就是使用这种方法。 • fd:number:从文件描述符读取密码。这可以用来通过管道传递数据,适用于需要动态提供密码的场景。 • stdin:从标准输入读取密码。这种方式会在命令执行时提示用户输入密码,适合交互式使用,但不适合自动化脚本。
三、使用SHC工具进行加密解密
shc是shell编译器(Shell Compiler)的缩写, 它可以对shell脚本进行编译和加密。它能够将shell脚本编译为可执行的二进制文件,其中包含了脚本的功能和逻辑,而不暴露源代码。shc在github托管地址:https://github.com/neurobin/shc/releases
shc工具安装
源码下载shc工具并编译安装
[root@localhost ~]# wget http://www.datsi.fi.upm.es/~frosal/sources/shc-3.8.9b.tgz
[root@localhost ~]# tar -zxvf shc-4.0.3.tar.gz
[root@localhost ~]# cd shc-4.0.3
[root@localhost shc-4.0.3]#./configure
[root@localhost shc-4.0.3]# make
[root@localhost shc-4.0.3]# make installshc工具使用帮助
下面是shc比较常用的参数说明,更多参数说明请参考man手册或官方文档。
使用shc工具加密shell脚本
#加密shell脚本
[root@localhost ~]# shc -v -f xunjian.sh
shc shll=bash
shc [-i]=-c
shc [-x]=exec'%s'"$@"
shc [-l]=
shc opts=
shc: cc xunjian.sh.x.c -o xunjian.sh.x
shc: strip xunjian.sh.x
shc: chmod ug=rwx,o=rx xunjian.sh.x
#加密完成后可以发现生成了两个文件
[root@localhost ~]# ll
......
-rw-------1 root root 56Dec2409:49 xunjian.sh
-rwxrwxr-x 1 root root 15312Dec2517:22 xunjian.sh.x
-rw-------1 root root 18023Dec2517:22 xunjian.sh.x.c
#我们使用file命令查看文件的类型
[root@localhost ~]# file xunjian.sh
xunjian.sh:Bourne-Again shell script, ASCII text executable
[root@localhost ~]# file xunjian.sh.x
xunjian.sh.x: ELF 64-bit LSB executable, x86-64, version 1(SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2,BuildID[sha1]=511a7ac43e893dff1a52999c8ba3e4cc236bc554,for GNU/Linux3.2.0, stripped
[root@localhost ~]# file xunjian.sh.x.c
xunjian.sh.x.c: C source, ASCII text正如上面输出的一样,加密完成后生成了两个文件:
• xunjian.sh是原始的未加密shell脚本(执行加密生成新的可执行二进制文件后便可以删除了) • xunjian.sh.x是加密过后的可执行的二进制文件。 • xunjian.sh.x.c是xunjian.sh文件的C源代码,也就是说编译该C源代码文件可以创建上面加密的xunjian.sh.x文件,(可以删除)
执行加密后的shell脚本文件
[root@localhost ~]#./xunjian.sh.x
#可以发现加密后的脚本文件能够正常执行
[root@localhost ~]# ll -h /tmp/all.sql
-rw-------1 root root 3.8MDec2517:22/tmp/all.sql设定加密后的Shell脚本过期时间及过期提示信息
shc还可以通过-e参数设定加密脚本有效执行期限,编译生成的可执行二进制文件在过了这个有效时间后,便不能执行,将收到错误消息。到期日期以dd/mm/yyyy 格式指定。还可以通过-m参数指定提示信息
#创建带有过期时间的加密脚本并给与过期提示信息
[root@localhost ~]# shc -e 20/12/2024-m "the script has expired, please contact your provierder [email protected]"-v -f xunjian.sh
shc shll=bash
shc [-i]=-c
shc [-x]=exec'%s'"$@"
shc [-l]=
shc opts=
shc: cc xunjian.sh.x.c -o xunjian.sh.x
shc: strip xunjian.sh.x
shc: chmod ug=rwx,o=rx xunjian.sh.x
[root@localhost ~]# ll xunjian.sh*
-rw-------1 root root 56Dec1821:08 xunjian.sh
-rwxrwxr-x 1 root root 15KDec2521:20 xunjian.sh.x
-rw-r--r--1 root root 18KDec2521:20 xunjian.sh.x.c
#如果尝试执行已过期的加密二进制文件,会打印设置的过期提示信息
[root@localhost ~]#./xunjian.sh.x
./xunjian.sh.x: has expired!
the script has expired, please contact your provierder 1234@foxmail.com如何解密SHc加密的.sh.x文件?
加密完成了,那应该如何解密SHc加密的*.sh.x文件,这便要用到UnSHc。但需要说明的是:在shc 4.0.3中,纳入了许多结构性更改,现在shc利用了Linux内核本身提供的各种安全机制。因此,如果使用的是新版shc,当前版本的UnSHc几乎不可能提取出原始的Shell脚本。注意:这只是现在不能,不代表以后不能,如果你能读懂源代码,对UnSHc加密脚本做加工,那也没什么不可能
工具下载地址:https://github.com/yanncam/UnSHc/blob/master/latest/unshc.sh,其实就是一个shell脚本。
#下载后授权并查看帮助如何使用
[root@localhost ~]# chmod +x unshc.sh
[root@localhost ~]#./unshc.sh -h
_ _ _____ _ _
||||/ ___||||
||||_ __ \ `--.| |_| | ___
| | | | '_ \ `--. \ _ |/ __|
||_||||/\__//|||(__
\___/|_||_\____/\_||_/\___|
---UnSHc-The shc decrypter.
---Version:0.8
------------------------------
UnSHcis used to decrypt script encrypted withSHc
Original idea fromLuizOctavioDuarte(LOD)
Updatedand modernized byYann CAM
-SHc:[http://www.datsi.fi.upm.es/~frosal/]
-UnSHc:[https://www.asafety.fr/unshc-the-shc-decrypter/]
------------------------------
[*]Usage:./unshc.sh [OPTIONS]<file.sh.x>
-h |--help :printthis help message
-a OFFSET |--arc4 OFFSET : specify the arc4() offset arbitrarily (without 0x prefix)
-d DUMPFILE |--dumpfile DUMPFILE : provide an objectdump file (objdump -D script.sh.x > DUMPFILE)
-s STRFILE |--stringfile STRFILE : provide a stringdump file (objdump -s script.sh.x > STRFILE)
-o OUTFILE |--outputfile OUTFILE : indicate the output file name
[*] e.g :
./unshc.sh script.sh.x
./unshc.sh script.sh.x -o script_decrypted.sh
./unshc.sh script.sh.x -a 400f9b
./unshc.sh script.sh.x -d /tmp/dumpfile -s /tmp/strfile
./unshc.sh script.sh.x -a 400f9b-d /tmp/dumpfile -s /tmp/strfile -o script_decrypted.sh对shc-4.0.3版本加密的二进制文件做解密确认解密失败,无法解密
[root@localhost ~]#./unshc.sh xunjian.sh.x
_ _ _____ _ _
||||/ ___||||
||||_ __ \ `--.| |_| | ___
| | | | '_ \ `--. \ _ |/ __|
||_||||/\__//|||(__
\___/|_||_\____/\_||_/\___|
---UnSHc-The shc decrypter.
---Version:0.8
------------------------------
UnSHcis used to decrypt script encrypted withSHc
Original idea fromLuizOctavioDuarte(LOD)
Updatedand modernized byYann CAM
-SHc:[http://www.datsi.fi.upm.es/~frosal/]
-UnSHc:[https://www.asafety.fr/unshc-the-shc-decrypter/]
------------------------------
[*]Input file name to decrypt [xunjian.sh.x]
[-]Unable to define arc4() call address...对shc-3.8.9b版本加密的二进制文件做解密确认解密成功
[root@localhost ~]#./unshc.sh xunjian.sh.x -o /tmp/script_decrypted.sh
_ _ _____ _ _
||||/ ___||||
||||_ __ \ `--.| |_| | ___
| | | | '_ \ `--. \ _ |/ __|
||_||||/\__//|||(__
\___/|_||_\____/\_||_/\___|
---UnSHc-The shc decrypter.
---Version:0.8
------------------------------
UnSHcis used to decrypt script encrypted withSHc
Original idea fromLuizOctavioDuarte(LOD)
Updatedand modernized byYann CAM
-SHc:[http://www.datsi.fi.upm.es/~frosal/]
-UnSHc:[https://www.asafety.fr/unshc-the-shc-decrypter/]
------------------------------
[*]Input file name to decrypt [xunjian.sh.x]
[+]Output file name specified [/tmp/script_decrypted.sh]
[+] ARC4 address call candidate :[0x40142a]
[*]Extracting each args address and size for the 14 arc4() calls with address [0x40142a]...
[0]Workingwithvar address at offset [0x404372](0x2a bytes)
[1]Workingwithvar address at offset [0x404120](0x1 bytes)
[2]Workingwithvar address at offset [0x404189](0xa bytes)
[3]Workingwithvar address at offset [0x40433c](0x3 bytes)
[4]Workingwithvar address at offset [0x4043a4](0xf bytes)
[5]Workingwithvar address at offset [0x4043b4](0x1 bytes)
[6]Workingwithvar address at offset [0x404357](0x16 bytes)
[7]Workingwithvar address at offset [0x404321](0x16 bytes)
[8]Workingwithvar address at offset [0x404199](0x13 bytes)
[9]Workingwithvar address at offset [0x404121](0x1 bytes)
[10]Workingwithvar address at offset [0x40433f](0x1 bytes)
[11]Workingwithvar address at offset [0x40412c](0x39 bytes)
[12]Workingwithvar address at offset [0x404174](0x13 bytes)
[13]Workingwithvar address at offset [0x404343](0x13 bytes)
[*]Extracting password...
[+] PWD address found :[0x4041ee]
[+] PWD size found :[0x100]
[*]Executing[/tmp/Kocrob] to decrypt [xunjian.sh.x]
[*]Retrieving initial source code in[/tmp/script_decrypted.sh]
[*]Alldone!
#查看解密后文件确认能正常看到文件内容
[root@localhost ~]# cat /tmp/script_decrypted.sh
#!/bin/bash
mysqldump -uroot -pMy12SQL -A>/tmp/all.sql总结
不同加密方法的优缺点
1、Base64 编码
• 优点:简单易用,适合简单的隐藏需求。 • 缺点:不是真正的加密方式,任何人都可以轻松解码。不适合保护敏感信息。
2、OpenSSL 加密
• 优点:提供强加密算法(如 AES-256-CBC),支持多种安全特性(如加盐、PBKDF2),适合保护敏感信息。 • 缺点:相对复杂,需要管理密码文件和依赖项。
3、shc 工具
• 优点:可以编译 Shell 脚本为二进制文件,防止直接查看脚本内容。 • 缺点:并不是真正的编译器,生成的二进制文件仍然依赖于原始 Shell 解释器;安全性有限,有经验的用户可以通过反向工程恢复原始脚本。
最佳实践
• 选择合适的加密方法:根据具体的敏感程度和应用场景选择最合适的加密方法。对于高敏感度的信息,推荐使用 OpenSSL 提供的强加密算法。 • 安全管理密码:无论是使用 OpenSSL 还是 shc,都应确保密码的安全管理,避免泄露。可以考虑使用环境变量或单独的密码文件,并严格限制其访问权限。 • 定期审查和更新:定期检查和更新密码及权限设置,以应对潜在的安全威胁。确保所有依赖库和环境变量在目标机器上正确配置。 • 备份和删除原始文件:在加密前,请确保有原始文件的备份。一旦加密过程完成,原始文件最好删除或妥善保管,以免泄露未加密的内容。 • 配置文件权限控制:严格限制敏感配置文件的访问权限,确保只有授权用户可以读取。