Solved

decrypting an AES encrypted file in ASP

Posted on 2010-08-19
11
494 Views
Last Modified: 2012-05-10
I have never worked with AES encryption before. I have files being sent to my server which are encrypted with a 128-bit key that I need to decrypt in order to extract the data. I'm really not quite sure how to proceed, the file isn't a plain text file that I can open with a text editor. So I assume I also cannot use the File System Object OpenTextFile to get access to the encrypted data. How do I even get at the data in order to decrypt it? Need a starting point. Thank you!
0
Comment
Question by:bbdesign
  • 6
  • 5
11 Comments
 
LVL 29

Expert Comment

by:Badotz
Comment Utility
It is probably a text file, and so FSO should allow you to open/read the content.

It is decrypting the content that will be the issue. There are countless examples on the web, so that part should not be too hard, either.
0
 

Author Comment

by:bbdesign
Comment Utility
If I try to open it with a text editor, I get garbage characters:

DJ$.X0f8WáMŸa•ÅH&"ñl°¿@hn¿æ5ÀÓ+·î:õèÔ9\ $'êç`L÷ü¿

Non-ASCII. But if you think FSO will work, I will give it a try.
0
 
LVL 29

Expert Comment

by:Badotz
Comment Utility
It isn't "garbage", it is AES-encrypted text.
0
 

Author Comment

by:bbdesign
Comment Utility
OK, so I'm sort of on the right track. I setup a script to open the file with FSO:

set objFILE=objFSO.OpenTextFile

...then I did:

response.write(objFILE.ReadAll)

See attached screenshot. The top box in red is what I see if I open the file directly into a text editor. The bottom red box is the source code of the ASP page where I did the response.write above.

Shouldn't I expect these to be identical?
Picture-1.jpg
0
 
LVL 29

Accepted Solution

by:
Badotz earned 500 total points
Comment Utility
Looking at encoded AES text is pointless.

Find a web site that lets you encrypt and decrypt AES, paste in the encoded text, your password, key and anything else it requires and see if it works.

What "Response.Write" passes up to the client may be different than what you see in Notepad.
0
Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

 

Author Comment

by:bbdesign
Comment Utility
I'm having a hard time finding anything that I can do a quick check with. Neither of these work:

http://www.chilkatsoft.com/js-aes-decrypt.asp
http://www.file-encrypter.com

These types of searches produce Google results that are so full of ads and spam that they're pretty much useless.

If a tool asks me to copy-and-paste text into a field in a web browser, I just open my file in a text editor, copy, then paste? It seems the encrypted data can't be moved around as easily as regular text.

If you have any other advice I would really appreciate it.
0
 
LVL 29

Expert Comment

by:Badotz
Comment Utility
I'm not sure how much text you can decrypt here, but

http://www.movable-type.co.uk/scripts/aes.html

provides details on AES. Give it a look, and copy/paste the code into your own page to see if it will work for you.
0
 

Author Comment

by:bbdesign
Comment Utility
That didn't do anything, at least with my code (when I open it to copy, it is several lines, that input field only had one).
0
 
LVL 29

Expert Comment

by:Badotz
Comment Utility
Then perhaps "copy/paste the code into your own page to see if it will work for you."
0
 

Author Comment

by:bbdesign
Comment Utility
OK, I'm going to close this out for now. Thanks for your help. At this point, I'm not even sure the file my client sent me is a valid AES encrypted file. What a mess.
0
 
LVL 29

Expert Comment

by:Badotz
Comment Utility
Not sure I deserved points, but thanks.
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

Article by: btan
Provide an easy one stop to quickly get the relevant information on common asked question on Ransomware in Expert Exchange.
SSL stands for “Secure Sockets Layer” and an SSL certificate is a critical component to keeping your website safe, secured, and compliant. Any ecommerce website must have an SSL certificate to ensure the safe handling of sensitive information like…
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

6 Experts available now in Live!

Get 1:1 Help Now