A WhatsApp mcrypt1 attachment decryption method, device, and related media
By obtaining WhatsApp backup data, building a download link and extracting the backup key, and calculating the encryption key and offset value to decrypt the mcrypt1 attachment, the problem of the existing technology that mcrypt1 type backup data cannot be quickly and effectively decrypted is solved, and fast and effective data decryption and viewing are achieved.
Patent Information
- Application Number
- CN202211379055.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-04
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2042-11-04
AI Technical Summary
The existing technology cannot quickly and effectively decrypt and view WhatsApp's mcrypt1 type backup data.
By obtaining WhatsApp backup data, constructing a download link to download the mcrypt1 attachment, extracting the backup key, calculating the encryption key and offset value, and using these keys and values to decrypt the mcrypt1 attachment.
It enables fast and effective decryption and viewing of mcrypt1 type backup data, ensuring user data security.
Smart Images

Figure CN115695026B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of backup data decryption, and in particular to a method and device for decrypting mcrypt1 attachments of WhatsApp and related media. Background Art
[0002] WhatsApp Messenger, also known as WhatsApp, is a cross-platform encrypted instant messaging application for smartphones owned by Meta. Conventionally, because WhatsApp transfers backup data to Google Drive as application data, downloading backup data from Google Drive is normally only possible through WhatsApp. This process requires logging into the corresponding account through WhatsApp and accessing the backup restore interface to download the backup from Google Drive to the local computer. If users wish to download this backup data themselves, they must use other methods.
[0003] Currently, the only decryption solutions available for WhatsApp encryption are crypt12 and crypt14 databases. There are no decryption solutions for mcrypt1 attachment encryption. Even if it were possible to directly download backup data from Google Drive, the downloaded backup data would be encrypted using mcrypt1, and there is currently no decryption solution. Therefore, how to quickly and effectively enable users to decrypt and view mcrypt1 backup data is a challenge. Summary of the Invention
[0004] The embodiments of the present invention provide a method, device, and related medium for decrypting mcrypt1 attachments for WhatsApp, aiming to solve the problem in the prior art that WhatsApp users cannot quickly and effectively decrypt and view mcrypt1 type backup data.
[0005] In a first aspect, an embodiment of the present invention provides a method for decrypting an mcrypt1 attachment of WhatsApp, comprising:
[0006] Obtain WhatsApp backup data on the target device; wherein the WhatsApp backup data includes an account backup list and a backup file list;
[0007] Construct a download link corresponding to the WhatsApp backup data according to the backup file list, and use the download link to download the corresponding mcrypt1 attachment;
[0008] Extract the backup key stored on the target device through administrator privileges or downgraded backup;
[0009] Calculate a first encryption key based on the backup key, and use the first encryption key to decrypt the encrypted data and metadata information in the WhatsApp backup data to obtain attribute information of the mcrypt1 attachment;
[0010] A second encryption key and an offset value are calculated based on the backup key, and the mcrypt1 attachment is decrypted using the second encryption key and the offset value to obtain the decrypted mcrypt1 attachment.
[0011] In a second aspect, an embodiment of the present invention provides a WhatsApp mcrypt1 attachment decryption device, comprising:
[0012] A backup data acquisition unit, configured to acquire WhatsApp backup data on a target device; wherein the WhatsApp backup data includes an account backup list and a backup file list;
[0013] An encrypted data acquisition unit, configured to construct a download link corresponding to the WhatsApp backup data according to the backup file list, and download the corresponding mcrypt1 attachment using the download link;
[0014] A backup key extraction unit, configured to extract the backup key stored on the target device through administrator privileges or downgraded backup;
[0015] a first data decryption unit, configured to calculate a first encryption key based on the backup key, and use the first encryption key to decrypt the encrypted data and metadata information in the WhatsApp backup data to obtain attribute information of the mcrypt1 attachment;
[0016] The second data decryption unit is configured to calculate a second encryption key and an offset value based on the backup key, and decrypt the mcrypt1 attachment using the second encryption key and the offset value to obtain the decrypted mcrypt1 attachment.
[0017] In a third aspect, an embodiment of the present invention provides a computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the mcrypt1 attachment decryption method for WhatsApp of the first aspect when executing the computer program.
[0018] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, wherein a computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the WhatsApp mcrypt1 attachment decryption method of the first aspect is implemented.
[0019] An embodiment of the present invention provides a method for decrypting WhatsApp mcrypt1 attachments. The method comprises obtaining WhatsApp backup data on a target device and downloading the corresponding mcrypt1 attachment, extracting the backup key stored on the target device, calculating a first encryption key based on the backup key, and using the first encryption key to decrypt the encrypted data and metadata information in the WhatsApp backup data to obtain attribute information of the mcrypt1 attachment. A second encryption key and an offset value are calculated based on the backup key, and the second encryption key and the offset value are used to decrypt the mcrypt1 attachment to obtain the decrypted mcrypt1 attachment. The present invention decrypts mcrypt1 attachments by extracting the backup key from the target device and combining it with the downloaded backup data, enabling users to quickly and efficiently decrypt and view mcrypt1-type backup data.
[0020] The embodiment of the present invention also provides a WhatsApp mcrypt1 attachment decryption device, computer equipment and storage medium, which also have the above-mentioned beneficial effects. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0022] Figure 1 A schematic diagram of a flow chart of a method for decrypting an mcrypt1 attachment in WhatsApp provided by an embodiment of the present invention;
[0023] Figure 2 Another schematic diagram of a flow chart of a method for decrypting an mcrypt1 attachment in WhatsApp provided by an embodiment of the present invention;
[0024] Figure 3 A schematic block diagram of a WhatsApp mcrypt1 attachment decryption device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0025] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0026] It will be understood that when used in this specification and the appended claims, the terms “comprises” and “comprising” indicate the presence of described features, integers, steps, operations, elements and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof.
[0027] It should also be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the present invention. As used in the specification and appended claims, the singular forms "a," "an," and "the" are intended to include the plural forms unless the context clearly indicates otherwise.
[0028] It should be further understood that the term "and / or" used in the present description and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.
[0029] See below Figure 1 , Figure 1 A flowchart of a method for decrypting an mcrypt1 attachment of WhatsApp provided by an embodiment of the present invention specifically includes steps S101 to S105.
[0030] S101. Obtaining WhatsApp backup data on a target device; wherein the WhatsApp backup data includes an account backup list and a backup file list;
[0031] S102, constructing a download link corresponding to the WhatsApp backup data according to the backup file list, and using the download link to download the corresponding mcrypt1 attachment;
[0032] S103, extracting the backup key stored on the target device through administrator privileges or downgraded backup;
[0033] S104. Calculate a first encryption key based on the backup key, and use the first encryption key to decrypt the encrypted data and metadata in the WhatsApp backup data to obtain attribute information of the mcrypt1 attachment.
[0034] S105. Calculate a second encryption key and an offset value based on the backup key, and decrypt the mcrypt1 attachment using the second encryption key and the offset value to obtain the decrypted mcrypt1 attachment.
[0035] Combine Figure 1 and Figure 2 As shown, in step S101, the first step is to prepare for resource acquisition before decrypting the mcrypt1 attachment, that is, obtaining the WhatsApp backup data on the target device; wherein, the WhatsApp backup data includes an account backup list and a backup file list; WhatsApp users use Google Drive for cloud backup, and back up chat data to the user's corresponding Google Drive account, and the chat data includes text chat information (that is, the WhatsApp backup data) and attachment information (that is, the mcrypt1 attachment), wherein the attachment information includes video, audio, pictures, documents, emoticons and stickers, etc.
[0036] In one embodiment, step S101 includes:
[0037] Obtain application data request permission through the Google Drive server, and use the credential token returned by the application data request permission to obtain the account backup list; send application backup data request information to the Google Drive server according to the account backup list, receive the returned credential token and obtain the backup file list.
[0038] In this embodiment, a successfully logged-in Google Drive account is used to obtain WhatsApp backup data on the Google Drive. The account backup list in the WhatsApp backup data is first obtained, and a request message is sent to the Google Drive server to obtain the application data request permission, corresponding to the service "appsbackup." The returned credential token is then used to obtain the account backup list on the Google Drive, which is the WhatsApp account (mobile phone number). Next, based on the obtained account backup list, WhatsApp is simulated to send a request message to the Google Drive server to obtain application backup data, corresponding to the service "drive.appdata." The returned credential token is then used to obtain the backup file list on the Google Drive, which is primarily a list of files for each WhatsApp account, including file name, upload time, file size, encrypted data, metadata, etc. It should be noted that the corresponding field of the returned credential token is "authorization." When the API interface requires access control, interface authentication can be used, that is, this credential can be used to form a BearerToken (token) to call the interface.
[0039] In step S102, the Google Drive account after successful login simulates the use of WhatsApp permissions to apply for a download credential, and then combines the backup file list in the WhatsApp backup data to construct a download link to download the corresponding mcrypt1 attachment; the mcrypt1 attachment here is the attachment information in step S101. When the attachment information was previously backed up in the cloud through the Google Drive, there was no encryption measure, and the attachment information was directly uploaded to the Google Drive as a file. The text chat information and attachment information of WhatsApp users cannot be securely protected on the Google Drive; therefore, in order to better protect the user's attachment chat data, WhatsApp launched an end-to-end encryption function, which allows the user's chat attachment information to be encrypted in the mcrypt1 format before being uploaded to the Google Drive.
[0040] In one embodiment, step S102 includes:
[0041] Send a request message for downloading the WhatsApp backup data to the Google Drive server and receive a returned credential token; parse the backup file list and construct a download link for the mcrypt1 attachment, and download the mcrypt1 attachment according to the download link and the credential token.
[0042] In this embodiment, WhatsApp is simulated to send a request message to the Google Drive server to download the WhatsApp backup data, the corresponding service is "drive.file", and then a returned credential token is received; the backup file list in the obtained WhatsApp backup data is parsed to form a download link for the mcrypt1 attachment, and then a request to download the mcrypt1 attachment is sent to the Google Drive server in combination with the returned credential token, and the mcrypt1 attachment of the corresponding WhatsApp account on the Google Drive is downloaded. It should be noted that the credential token returned in step S102 and the credential token returned in step S101 are both credential tokens, but the access rights corresponding to the two credential tokens are different, and different access rights are determined according to the requested service.
[0043] In step S103, after the WhatsApp program on the target device uses the end-to-end function to back up data, a file named "encryption_backup.key" is generated at the path " / data / data / com.whatsapp / files / " on the target device, and its corresponding Chinese name is backup key; the backup key contains the key required for decrypting the encrypted database, and the specific key data is the last 32 bytes of the binary data of the backup key; it should be noted that the path " / data / data / com.whatsapp / files / " is a private directory and access is normally denied; this private directory can be directly accessed with administrator privileges and the backup key can be extracted, or the backup key can be extracted using the downgrade backup method; of course, if there are other ways to extract the backup key, they are also feasible.
[0044] In step S104, a first encryption key is calculated based on the backup key, and the encrypted data and metadata information in the WhatsApp backup data are respectively decrypted using the first encryption key to obtain attribute information of the mcrypt1 attachment. Specifically, after decrypting the metadata information, specific information of the mcryp1 attachment is obtained, such as the specific path, name, md5 hash value, file size, and upload time. After decrypting the encrypted data, the total data size and number of the mcryp1 attachments are obtained.
[0045] In one embodiment, the step S104 includes:
[0046] A SHA256 algorithm operation is performed on the backup key and a predetermined character string to obtain the first encryption key for decrypting the metadata information.
[0047] Furthermore, the encrypted data is Base64 decoded to obtain decoded first binary data; the first encryption key and the first binary data are operated by AES CBC algorithm to obtain total attribute information of the mcrypt1 attachment, and the total attribute information includes the total data size and the number of attachments of all the mcrypt1 attachments.
[0048] Furthermore, the metadata information is Base64 decoded to obtain decoded second binary data; the first encryption key and the second binary data are subjected to AES CBC algorithm operation to obtain single attribute information of the mcrypt1 attachment, and the single attribute information includes attribute information of a single mcrypt1 attachment.
[0049] In this embodiment, the extracted backup key is subjected to an HMAC (Hash Message Authentication Code, hereinafter the same) SHA256 algorithm operation with the predetermined string "metadata encryption" to decrypt the first encryption key of the metadata information. Specifically, the Secure Hash Algorithm (SHA) is a family of cryptographic hash functions and a FIPS-certified secure hash algorithm that can calculate the fixed-length string corresponding to a digital message. SHA-2, named after the Secure Hash Algorithm 2 (SHA-2), is a cryptographic hash function that can calculate the fixed-length string corresponding to a digital message. SHA-256 is the abbreviation of SHA-224, a cryptographic hash function algorithm standard developed by the U.S. National Security Agency and released by the National Institute of Standards and Technology (NIST) in 2001. It is one of the SHA algorithms and the successor of SHA-1. It can be further divided into six different algorithm standards, including: SHA-224, SHA-256, SHA-384, SHA-512, SHA-512 / 224, and SHA-512 / 256. SHA-256 (SHA256 algorithm, the same below) is used in this embodiment.
[0050] Furthermore, after obtaining the first encryption key for decrypting the metadata information, the encrypted data in the file backup list, specifically identified as "encryptedData", can be decrypted; the encrypted data is decoded by Base64 (Base64 is a method for representing binary data based on 64 printable characters) to obtain the first binary data after decoding; it should be noted that the format of the binary data (applicable to both the first and second binary data mentioned in this embodiment) is that the first 17 bytes (the first byte is the size of the IV value, the next 16 bytes are the IV value, and the size of the IV value is fixed to 16) are the IV value plus the size, the 33 bytes after the 17 bytes (the first byte is the size of the check value, the next 32 bytes are the check value, and the size of the check value is fixed to 32) are the check value plus the size, and the bytes after that are the actual encrypted data; the first encryption key is used with the parsed IV value and the actual encrypted data to perform an AES CBC algorithm (cipher block chaining mode, the same below) to obtain the total attribute information of the mcrypt1 attachment, which includes the total data size and the number of attachments of all the mcrypt1 attachments.
[0051] Furthermore, the metadata information in the file backup list is decrypted, specifically identified as "metadata"; the format type of the metadata information is the same as the format type of the encrypted data (encryptedData), the metadata information is Base64 decoded to obtain the decoded second binary data, and the same method of decrypting the encrypted data is used to parse and obtain the corresponding IV value, check value and true encrypted data, i.e., the second binary data; the first encryption key and the second binary data are subjected to AES CBC algorithm operation to obtain the single attribute information of the mcrypt1 attachment, and the single attribute information includes attribute information of a single mcrypt1 attachment, such as the specific path, name, md5Hash value, file size and upload time, etc.
[0052] In step S105, a second encryption key and an offset value are calculated based on the backup key, and the mcrypt1 attachment is decrypted using the second encryption key and the offset value to obtain the decrypted mcrypt1 attachment. At this point, the user can directly view the content of the mcrypt1 attachment backed up by WhatsApp on the Google Drive.
[0053] In one embodiment, step S105 includes:
[0054] Convert the file name of the mcrypt1 attachment into third binary data, and perform a SHA256 algorithm operation on the backup key and empty data to obtain a temporary key; perform a hash message authentication code operation on the temporary key, the empty data, integer 1, and the third binary data to obtain the second encryption key; perform a hash message authentication code operation on the temporary key, the empty data, integer 2, and the third binary data to obtain the offset value; based on the AES GCM algorithm, decrypt the mcrypt1 attachment using the second encryption key and the offset value to obtain the decrypted mcrypt1 attachment.
[0055] In this embodiment, the file name of the mcrypt1 attachment consists of 64 characters, which correspond to 32 bits of binary data. First, the file name of the mcrypt1 attachment is converted into the third binary data. Then, the backup key and the empty data are hashed using the SHA256 algorithm to obtain the temporary key. The temporary key is hashed using the empty data, integer 1, and the third binary data to obtain the second encryption key. The temporary key is hashed using the empty data, integer 2, and the third binary data to obtain the offset value. After calculating the second encryption key and the offset value, the mcrypt1 attachment is decrypted using the second encryption key and the offset value based on the AES GCM algorithm to obtain the decrypted mcrypt1 attachment. This completes the decryption process for the mcrypt1 attachment. It should be noted that the empty data can be understood as a temporary variable. When initialized, the temporary variable is empty data. The temporary variable will be assigned a value after each operation. The specific variable parameters are determined by the actual situation.
[0056] Combine Figure 3 As shown, Figure 3 A schematic block diagram of a WhatsApp mcrypt1 attachment decryption device provided in an embodiment of the present invention, wherein the WhatsApp mcrypt1 attachment decryption device 300 includes:
[0057] A backup data acquisition unit 301 is configured to acquire WhatsApp backup data on a target device; wherein the WhatsApp backup data includes an account backup list and a backup file list;
[0058] An encrypted data acquisition unit 302 is configured to construct a download link corresponding to the WhatsApp backup data according to the backup file list, and download the corresponding mcrypt1 attachment using the download link;
[0059] The backup key extraction unit 303 is configured to extract the backup key stored on the target device through administrator privileges or downgraded backup;
[0060] A first data decryption unit 304 is configured to calculate a first encryption key based on the backup key, and use the first encryption key to decrypt the encrypted data and metadata information in the WhatsApp backup data to obtain attribute information of the mcrypt1 attachment;
[0061] The second data decryption unit 305 is configured to calculate a second encryption key and an offset value according to the backup key, and decrypt the mcrypt1 attachment using the second encryption key and the offset value to obtain the decrypted mcrypt1 attachment.
[0062] In this embodiment, the backup data acquisition unit 301 first acquires the WhatsApp backup data on the target device; the encrypted data acquisition unit 302 constructs a download link corresponding to the WhatsApp backup data according to the backup file list, and uses the download link to download the corresponding mcrypt1 attachment; the backup key extraction unit 303 extracts the backup key stored on the target device through administrator privileges or downgraded backup; the first data decryption unit 304 calculates a first encryption key according to the backup key, and uses the first encryption key to decrypt the encrypted data and metadata information in the WhatsApp backup data respectively to obtain attribute information of the mcrypt1 attachment; the second data decryption unit 305 calculates a second encryption key and an offset value according to the backup key, and uses the second encryption key and the offset value to decrypt the mcrypt1 attachment to obtain the decrypted mcrypt1 attachment.
[0063] In one embodiment, the backup data acquisition unit 301 includes:
[0064] a first acquiring unit, configured to acquire an application data request permission through a Google Drive server, and acquire the account backup list using a credential token returned by the application data request permission;
[0065] The second acquiring unit is configured to send a request message for application backup data to the Google Drive server according to the account backup list, receive a returned credential token, and acquire the backup file list.
[0066] In one embodiment, the encrypted data obtaining unit 302 includes:
[0067] A first sending unit, configured to send a request message for downloading the WhatsApp backup data to the Google Drive server and receive a returned credential token;
[0068] The first downloading unit is configured to parse the backup file list and construct a download link for the mcrypt1 attachment, and obtain the mcrypt1 attachment by downloading the link and the credential token.
[0069] In one embodiment, the first data decryption unit 304 includes:
[0070] The first calculation unit is used to perform a SHA256 algorithm operation on the backup key and a predetermined character string to obtain the first encryption key for decrypting the metadata information.
[0071] a first decoding unit, configured to perform Base64 decoding on the encrypted data to obtain decoded first binary data;
[0072] The second calculation unit is used to perform an AES CBC algorithm operation on the first encryption key and the first binary data to obtain total attribute information of the mcrypt1 attachments, where the total attribute information includes a total data size and the number of attachments of all the mcrypt1 attachments.
[0073] A second decoding unit, configured to perform Base64 decoding on the metadata information to obtain decoded second binary data;
[0074] The third calculation unit is configured to perform an AES CBC algorithm operation on the first encryption key and the second binary data to obtain single attribute information of the mcrypt1 attachment, where the single attribute information includes attribute information of a single mcrypt1 attachment.
[0075] In one embodiment, the second data decryption unit 305 includes:
[0076] a fourth computing unit, configured to convert the file name of the mcrypt1 attachment into third binary data, and perform a SHA256 algorithm operation on the backup key and the empty data to obtain a temporary key;
[0077] a fifth computing unit, configured to perform a hash message authentication code operation on the temporary key, the null data, the integer 1, and the third binary data to obtain the second encryption key;
[0078] a sixth calculating unit, configured to perform a hash message authentication code operation on the temporary key, the empty data, the integer 2, and the third binary data to obtain the offset value;
[0079] The seventh computing unit is configured to decrypt the mcrypt1 attachment based on the AES GCM algorithm using the second encryption key and the offset value to obtain the decrypted mcrypt1 attachment.
[0080] Since the embodiments of the apparatus part correspond to the embodiments of the method part, please refer to the description of the embodiments of the method part for the embodiments of the apparatus part, and they will not be repeated here.
[0081] The present invention also provides a computer-readable storage medium having a computer program stored thereon. When executed, the computer program can implement the steps provided in the above embodiments. The storage medium can include a USB flash drive, a mobile hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, among other media capable of storing program code.
[0082] The present invention also provides a computer device that may include a memory and a processor. The memory stores a computer program, and when the processor calls the computer program in the memory, the steps provided in the above embodiment can be implemented. Of course, the computer device may also include various network interfaces, a power supply, and other components.
[0083] The various embodiments in the specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same and similar parts between the various embodiments can be referred to each other. For the system disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part description. It should be pointed out that for ordinary technicians in this technical field, without departing from the principles of this application, several improvements and modifications can be made to this application, and these improvements and modifications also fall within the scope of protection of the claims of this application.
[0084] It should also be noted that, in this specification, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus comprising the element.
Claims
1. A method for decrypting mcrypt1 attachments of WhatsApp, characterized in that: include: Obtaining WhatsApp backup data on the target device; wherein the WhatsApp backup data includes an account backup list and a backup file list; Construct a download link corresponding to the WhatsApp backup data according to the backup file list, and use the download link to download the corresponding mcrypt1 attachment; Extract the backup key stored on the target device through administrator privileges or downgraded backup; Calculate a first encryption key based on the backup key, and use the first encryption key to decrypt the encrypted data and metadata information in the WhatsApp backup data to obtain attribute information of the mcrypt1 attachment; Calculating a second encryption key and an offset value based on the backup key, and decrypting the mcrypt1 attachment using the second encryption key and the offset value to obtain the decrypted mcrypt1 attachment; The method comprises: calculating a second encryption key and an offset value according to the backup key, decrypting the mcrypt1 attachment using the second encryption key and the offset value to obtain the decrypted mcrypt1 attachment, including: converting the file name of the mcrypt1 attachment into third binary data, and performing a SHA256 algorithm operation on the backup key and empty data to obtain a temporary key; performing a hash message authentication code operation on the temporary key, the empty data, an integer 1, and the third binary data to obtain the second encryption key; performing a hash message authentication code operation on the temporary key, the empty data, an integer 2, and the third binary data to obtain the offset value; and decrypting the mcrypt1 attachment using the second encryption key and the offset value based on the AES GCM algorithm to obtain the decrypted mcrypt1 attachment.
2. The mcrypt1 attachment decryption method for WhatsApp according to claim 1, wherein: The method of obtaining the WhatsApp backup data on the target device includes: Obtaining an application data request permission from a Google Drive server, and using a credential token returned by the application data request permission to obtain the account backup list; Send application backup data request information to the Google Drive server according to the account backup list, receive a returned credential token and obtain the backup file list.
3. The mcrypt1 attachment decryption method for WhatsApp according to claim 1, wherein: The step of constructing a download link corresponding to the WhatsApp backup data according to the backup file list, and downloading the corresponding mcrypt1 attachment using the download link, comprises: Sending a request message to the Google Drive server to download the WhatsApp backup data and receiving a returned credential token; Parse the backup file list and construct a download link for the mcrypt1 attachment, and download the mcrypt1 attachment according to the download link and the credential token.
4. The mcrypt1 attachment decryption method for WhatsApp according to claim 1, wherein: The step of calculating the first encryption key according to the backup key includes: A SHA256 algorithm operation is performed on the backup key and a predetermined character string to obtain the first encryption key for decrypting the metadata information.
5. The mcrypt1 attachment decryption method for WhatsApp according to claim 1, wherein: The method of using the first encryption key to decrypt the encrypted data and metadata information in the WhatsApp backup data to obtain information containing the mcrypt1 attachment includes: Performing Base64 decoding on the encrypted data to obtain decoded first binary data; An AES CBC algorithm is performed on the first encryption key and the first binary data to obtain total attribute information of the mcrypt1 attachments, where the total attribute information includes a total data size and the number of attachments of all the mcrypt1 attachments.
6. The mcrypt1 attachment decryption method for WhatsApp according to claim 1, wherein: The method of using the first encryption key to decrypt the encrypted data and metadata information in the WhatsApp backup data to obtain information including the mcrypt1 attachment further includes: Performing Base64 decoding on the metadata information to obtain decoded second binary data; An AES CBC algorithm operation is performed on the first encryption key and the second binary data to obtain single attribute information of the mcrypt1 attachment, where the single attribute information includes attribute information of a single mcrypt1 attachment.
7. A WhatsApp mcrypt1 attachment decryption device, characterized in that: include: A backup data acquisition unit, configured to acquire WhatsApp backup data on a target device; wherein the WhatsApp backup data includes an account backup list and a backup file list; An encrypted data acquisition unit, configured to construct a download link corresponding to the WhatsApp backup data according to the backup file list, and download the corresponding mcrypt1 attachment using the download link; A backup key extraction unit, configured to extract the backup key stored on the target device through administrator privileges or downgraded backup; a first data decryption unit, configured to calculate a first encryption key based on the backup key, and use the first encryption key to decrypt the encrypted data and metadata information in the WhatsApp backup data to obtain attribute information of the mcrypt1 attachment; A second data decryption unit, configured to calculate a second encryption key and an offset value according to the backup key, and decrypt the mcrypt1 attachment using the second encryption key and the offset value to obtain the decrypted mcrypt1 attachment; The second data decryption unit is specifically used to convert the file name of the mcrypt1 attachment into third binary data, and perform a SHA256 algorithm operation on the backup key and empty data to obtain a temporary key; perform a hash message authentication code operation on the temporary key, the empty data, integer 1 and the third binary data to obtain the second encryption key; perform a hash message authentication code operation on the temporary key, the empty data, integer 2 and the third binary data to obtain the offset value; based on the AES GCM algorithm, decrypt the mcrypt1 attachment using the second encryption key and the offset value to obtain the decrypted mcrypt1 attachment.
8. A computer device, characterized in that: The present invention comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the mcrypt1 attachment decryption method for WhatsApp according to any one of claims 1 to 6 is implemented.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the mcrypt1 attachment decryption method for WhatsApp according to any one of claims 1 to 6.