thinkphp微信开发:安全模式消息加解密,thinkphp解密
thinkphp微信开发:安全模式消息加解密,thinkphp解密
使用thinkphp官方的WeChat包,使用不同模式可以成功,但是安全模式就是不行,现将分析解决结果做下记录。
TRight
分析问题:
解密微信服务器消息老是不成功,下载下微信公众平台官方给出的解密文件和WechatCrypt.class.php进行比对发现也没有问题。用file_put_contents函数保存下解密后的文件进行分析。发现官方包解密的xml不是标准的xml格式,所以simplexml_load_string函数无法处理。
<span>/*</span><span>* * 对密文进行解密 * @param string $encrypt 密文 * @return string 明文 </span><span>*/</span> <span>public</span> <span>function</span> decrypt(<span>$encrypt</span><span>){ </span><span>//</span><span>BASE64解码</span> <span>$encrypt</span> = <span>base64_decode</span>(<span>$encrypt</span><span>); </span><span>//</span><span>打开加密算法模块</span> <span>$td</span> = mcrypt_module_open(MCRYPT_RIJNDAEL_128, '', MCRYPT_MODE_CBC, ''<span>); </span><span>//</span><span>初始化加密算法模块</span> mcrypt_generic_init(<span>$td</span>, <span>$this</span>->cyptKey, <span>substr</span>(<span>$this</span>->cyptKey, 0, 16<span>)); </span><span>//</span><span>执行解密</span> <span>$decrypt</span> = mdecrypt_generic(<span>$td</span>, <span>$encrypt</span><span>); </span><span>//</span><span>去除PKCS7补位</span> <span>$decrypt</span> = self::PKCS7Decode(<span>$decrypt</span>, mcrypt_enc_get_key_size(<span>$td</span><span>)); </span><span>//</span><span>关闭加密算法模块</span> mcrypt_generic_deinit(<span>$td</span><span>); mcrypt_module_close(</span><span>$td</span><span>); </span><span>if</span>(<span>strlen</span>(<span>$decrypt</span>) < 16<span>){ </span><span>throw</span> <span>new</span> \<span>Exception</span>("非法密文字符串!"<span>); } </span><span>//</span><span>去除随机字符串</span> <span>$decrypt</span> = <span>substr</span>(<span>$decrypt</span>, 16<span>); </span><span>//</span><span>获取网络字节序</span> <span>$size</span> = <span>unpack</span>("N", <span>substr</span>(<span>$decrypt</span>, 0, 4<span>)); </span><span>$size</span> = <span>$size</span>[1<span>]; </span><span>//</span><span>APP_ID</span> <span>$appid</span> = <span>substr</span>(<span>$decrypt</span>, <span>$size</span> + 4<span>); </span><span>//</span><span>验证APP_ID</span> <span>if</span>(<span>$appid</span> !== <span>$this</span>-><span>appId){ </span><span>throw</span> <span>new</span> \<span>Exception</span>("非法APP_ID!"<span>); } </span><span>//</span><span>明文内容</span> <span>$text</span> = <span>substr</span>(<span>$decrypt</span>, 4, <span>$size</span><span>); </span><span>return</span> <span>$text</span><span>; } </span><span>/*</span><span>* * PKCS7填充字符 * @param string $text 被填充字符 * @param integer $size Block长度 </span><span>*/</span> <span>private</span> <span>static</span> <span>function</span> PKCS7Encode(<span>$text</span>, <span>$size</span><span>){ </span><span>//</span><span>字符串长度</span> <span>$str_size</span> = <span>strlen</span>(<span>$text</span><span>); </span><span>//</span><span>填充长度</span> <span>$pad_size</span> = <span>$size</span> - (<span>$str_size</span> % <span>$size</span><span>); </span><span>$pad_size</span> = <span>$pad_size</span> ? : <span>$size</span><span>; </span><span>//</span><span>填充的字符</span> <span>$pad_chr</span> = <span>chr</span>(<span>$pad_size</span><span>); </span><span>//</span><span>执行填充</span> <span>$text</span> = <span>str_pad</span>(<span>$text</span>, <span>$str_size</span> + <span>$pad_size</span>, <span>$pad_chr</span>,<span> STR_PAD_RIGHT); </span><span>return</span> <span>$text</span><span>; } </span><span>/*</span><span>* * 删除PKCS7填充的字符 * @param string $text 已填充的字符 * @param integer $size Block长度 </span><span>*/</span> <span>private</span> <span>static</span> <span>function</span> PKCS7Decode(<span>$text</span>, <span>$size</span><span>){ </span><span>//</span><span>获取补位字符</span> <span>$pad_str</span> = <span>ord</span>(<span>substr</span>(<span>$text</span>, -1<span>)); </span><span>if</span> (<span>$pad_str</span> < 1 || <span>$pad_str</span> > <span>$size</span><span>) { </span><span>$pad_str</span>= 0<span>; } </span><span>return</span> <span>substr</span>(<span>$text</span>, 0, <span>strlen</span>(<span>$text</span>) - <span>$pad_str</span><span>); }</span>
解决方法:
输出的xml文件是这样的
<span>1</span> <span><</span><span>xml</span><span>></span> <span>2</span> <span><</span><span>ToUserName</span><span>></span><span><![CDATA[</span><span>gh_249aeb986d99</span><span>]]></span><span><</span><span>\/ToUserName</span><span>></span><span>\n </span><span>3</span> <span><</span><span>FromUserName</span><span>></span><span><![CDATA[</span><span>oopVmxHZaeQkDPsRcbpwXKkH-J2Q</span><span>]]></span><span><</span><span>\/FromUserName</span><span>></span><span>\n </span><span>4</span> <span><</span><span>CreateTime</span><span>></span>1448944621<span><</span><span>\/CreateTime</span><span>></span><span>\n </span><span>5</span> <span><</span><span>MsgType</span><span>></span><span><![CDATA[</span><span>text</span><span>]]></span><span><</span><span>\/MsgType</span><span>></span><span>\n </span><span>6</span> <span><</span><span>Content</span><span>></span><span><![CDATA[</span><span>\u7ecf\u7406</span><span>]]></span><span><</span><span>\/Content</span><span>></span><span>\n </span><span>7</span> <span><</span><span>MsgId</span><span>></span>6223169761311044588<span><</span><span>\/MsgId</span><span>></span><span>\n </span><span>8</span> <span><</span><span>\/xml</span><span>></span>
所以需要进行处理才能让simplexml_load_string处理
在输出的明文内容后面加上
<span>1</span> <span>//明文内容 </span><span>2</span> <span> $text = substr($decrypt, 4, $size); </span><span>3</span> <span>//去掉多余的内容 </span><span>4</span> $text=str_replace('<span><</span><span>\/','</', $text</span><span>); </span><span>5</span> <span> $text</span><span>=str_replace('>\n','>', </span><span>$text); </span><span>6</span> <span> return $text;</span>
安全模式就能正常使用了。

Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

Notepad++7.3.1
Easy-to-use and free code editor

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

Hot Topics











ThinkPHP6 routing parameters are processed in Chinese and complete acquisition. In the ThinkPHP6 framework, URL parameters containing special characters (such as Chinese and punctuation marks) are often processed...

Troubleshooting and solutions to the company's security software that causes some applications to not function properly. Many companies will deploy security software in order to ensure internal network security. ...

Discussion on the JS resource caching issue of Enterprise WeChat. When upgrading project functions, some users often encounter situations where they fail to successfully upgrade, especially in the enterprise...

H5 is more flexible and customizable, but requires skilled technology; mini programs are quick to get started and easy to maintain, but are limited by the WeChat framework.

H5. The main difference between mini programs and APP is: technical architecture: H5 is based on web technology, and mini programs and APP are independent applications. Experience and functions: H5 is light and easy to use, with limited functions; mini programs are lightweight and have good interactiveness; APPs are powerful and have smooth experience. Compatibility: H5 is cross-platform compatible, applets and APPs are restricted by the platform. Development cost: H5 has low development cost, medium mini programs, and highest APP. Applicable scenarios: H5 is suitable for information display, applets are suitable for lightweight applications, and APPs are suitable for complex functions.

Compatibility issues and troubleshooting methods for company security software and application. Many companies will install security software in order to ensure intranet security. However, security software sometimes...

Laravel and ThinkPHP are both popular PHP frameworks and have their own advantages and disadvantages in development. This article will compare the two in depth, highlighting their architecture, features, and performance differences to help developers make informed choices based on their specific project needs.

H5 development tools recommendations: VSCode, WebStorm, Atom, Brackets, Sublime Text; Mini Program Development Tools: WeChat Developer Tools, Alipay Mini Program Developer Tools, Baidu Smart Mini Program IDE, Toutiao Mini Program Developer Tools, Taro.
