🌐
Degoogle
kirsle.net › wizards › flask-session.cgi
Flask Session Cookie Decoder
"""Flask session cookie decoder.""" #import cgitb #cgitb.enable() import os import codecs import cgi import jinja2 from base64 import b64decode from itsdangerous import base64_decode import zlib import json import pygments from pygments.formatters import HtmlFormatter from pygments.lexers import PythonLexer, JsonLexer import uuid from werkzeug.http import parse_date from flask import Markup env = jinja2.Environment(loader=jinja2.FileSystemLoader(".")) def main(): form = get_form() # Pygments CSS source.
🌐
GitHub
github.com › noraj › flask-session-cookie-manager
GitHub - noraj/flask-session-cookie-manager: :cookie: Flask Session Cookie Decoder/Encoder · GitHub
Use flask_session_cookie_manager3.py with Python 3 and flask_session_cookie_manager2.py with Python 2. usage: flask_session_cookie_manager{2,3}.py [-h] {encode,decode} ... Flask Session Cookie Decoder/Encoder positional arguments: {encode,decode} sub-command help encode encode decode decode optional arguments: -h, --help show this help message and exit ·
Starred by 774 users
Forked by 93 users
Languages   Python 88.9% | Shell 11.1%
🌐
Noraj
noraj.github.io › flask-session-cookie-manager
Flask Session Cookie Decoder/Encoder | flask-session-cookie-manager
usage: flask_session_cookie_manager{2,3}.py decode [-h] [-s <string>] -c <string> optional arguments: -h, --help show this help message and exit -s <string>, --secret-key <string> Secret key -c <string>, --cookie-value <string> Session cookie value · $ python{2,3} flask_session_cookie_manager{2,3}.py encode -s '.{y]tR&sp&77RdO~u3@XAh#TalD@Oh~yOF_51H(QV};K|ghT^d' -t '{"number":"326410031505","username":"admin"}' eyJudW1iZXIiOnsiIGIiOiJNekkyTkRFd01ETXhOVEExIn0sInVzZXJuYW1lIjp7IiBiIjoiWVdSdGFXND0ifX0.DE2iRA.ig5KSlnmsDH4uhDpmsFRPupB5Vw ·
🌐
Readthedocs
flask-cookie-decode.readthedocs.io › en › latest › readme.html
1 flask-cookie-decode — flask-cookie-decode 0.4.3 documentation
Adds a cookie command to the built-in Flask CLI which will provide various tools for debugging the secure session cookie that Flask uses by default. flask cookie decode: decodes and verifies the signature of the session cookie
🌐
PyPI
pypi.org › project › flask-session-decoder
flask-session-decoder · PyPI
Once installed, you can import and instantiate the decoder like this: from flask_session_decoder import FlaskSessionDecoder decoder = FlaskSessionDecoder(secret_key="the-secret-key-of-the-flask-app-that-created-the-cookie")
      » pip install flask-session-decoder
    
Published   Dec 16, 2022
Version   0.1.0
🌐
Xin Fu
imfing.com › til › decode-flask-session-cookie
Decode Flask session cookie | Xin Fu
January 4, 2023 - import zlib import base64 def decode(cookie): """Decode a Flask cookie.""" try: compressed = False payload = cookie if payload.startswith('.'): compressed = True payload = payload[1:] data = payload.split(".")[0] data = base64.urlsafe_b64decode(data) if compressed: data = zlib.decompress(data) return data.decode("utf-8") except Exception as e: return "[Decoding error: are you sure this was a Flask session cookie?
🌐
PyPI
pypi.org › project › flask-cookie-decode
flask-cookie-decode · PyPI
Adds a cookie command to the built-in Flask CLI which will provide various tools for debugging the secure session cookie that Flask uses by default. flask cookie decode: decodes and verifies the signature of the session cookie
      » pip install flask-cookie-decode
    
Published   Mar 09, 2025
Version   0.4.3
🌐
Pentesttools
pentesttools.net › flask-session-cookie-manager-flask-session-cookie-decoder-encoder
Flask-Session-Cookie-Manager – Flask Session Cookie Decoder/Encoder – PentestTools
August 12, 2020 - $ python{2,3} flask_session_cookie_manager{2,3}.py decode -c 'eyJudW1iZXIiOnsiIGIiOiJNekkyTkRFd01ETXhOVEExIn0sInVzZXJuYW1lIjp7IiBiIjoiWVdSdGFXND0ifX0.DE2iRA.ig5KSlnmsDH4uhDpmsFRPupB5Vw' -s '.{y]tR&sp&77RdO~u3@XAh#TalD@Oh~yOF_51H(QV};K|ghT^d' {u'username': 'admin', u'number': '326410031505'}
Find elsewhere
🌐
GitHub
github.com › volfpeter › flask-session-decoder
GitHub - volfpeter/flask-session-decoder: Zero-dependency Flask session decoder · GitHub
Once installed, you can import and instantiate the decoder like this: from flask_session_decoder import FlaskSessionDecoder decoder = FlaskSessionDecoder(secret_key="the-secret-key-of-the-flask-app-that-created-the-cookie")
Author   volfpeter
Top answer
1 of 2
11

As Elias has already mentioned, the cookie can be decoded without the secret key, but it cannot be manipulated without it for obvious security reasons. If cookie tampering was as easy as that, nobody would use Flask sessions. Therefore, your task is to find the secret key, and since the SHA-1 hash function is non-reversible, you should turn your attention to the human factor.

That being said, you'll have to "guess" the secret key of the contest's careless programmer using brute force, and fortunately, Flask-Unsign can assist you with that.

You can install it via pip by using the following command:

pip3 install flask-unsign

but before using it, you will need a wordlist like rockyou, which you can download from the Kali Linux GitLab repository by using a command like the one below:

curl -JO https://gitlab.com/kalilinux/packages/wordlists/-/raw/kali/master/rockyou.txt.gz && gunzip rockyou.txt.gz
  • -J, --remote-header-name: Uses the server-specified Content-Disposition filename instead of extracting a filename from the URL when saving the file locally.
  • -O, --remote-name: Writes the output to a local file named like the remote file obtained, using the server-specified filename.

Now you can perform the brute force attack using the following command:

flask-unsign --unsign --cookie '.eJwtjkGKAzEMBL-S9TkHy5Yte96wP1jCIEvyJmxIYDxzCvn7-pBTUw1N18ut_c7jasMtPy932me4cYjYGO7svp-_t8fpw_24f7nL-3Kem83G1S37dtikm7rFQUJBRSOL1GKWVCoRC3ED7VAz9FKsVi9aO2RgJmgSi88VuQCmXghjaRZjSCqBDTm3qE1LAh8bGnuG3jAHCV4iZlAoPkhiAGghT9v1GLZ9bCbK2Pq6P__sMQuev2ZcKQFkMinJWhRSqB4hYyWv2oWre_8D5vtQyA.ZTUbZQ.erv_yZmYg44tiaJ0u8fqKailHUc' --no-literal-eval -w rockyou.txt   
  • The --no-literal-eval argument was used because Flask-Unsign assumes by default that each word in a given wordlist is enclosed in quotes. However, this is not the case with the rockyou wordlist.

and find the secret key after a few thousand attempts:

[*] Session decodes to: {'_flashes': [('success', 'Login successful!')], '_fresh': True, '_id': '154c4d4e7e37b36c58977ac7ab1df1961f88e990cd9f161aa71bc380694a8145f87438be3325dc2ae4a6b3dbd85103b4ea0a1fb462c20c3461d1802c5a111b26', '_user_id': '1', 'csrf_token': 'acd9eea9751167ec85eb3c7d1904164970ddfca9'}                       
[*] Starting brute-forcer with 8 threads..                                                                                                     
[+] Found secret key after 175360 attempts                                                                                                     
b'Galaxy'

Finally, having found the secret key, you can use it to sign your own cookie with modified session data according to your needs:

flask-unsign --sign --cookie "modified session data here" --secret 'Galaxy'
2 of 2
1

What you described is the expected behavior by design - the cookie can be decoded without the secret key, but it cannot be modified without it.

from documentation:

If you have set Flask.secret_key (or configured it from SECRET_KEY) you can use sessions in Flask applications. A session makes it possible to remember information from one request to another. The way Flask does this is by using a signed cookie. The user can look at the session contents, but can’t modify it unless they know the secret key, so make sure to set that to something complex and unguessable.

🌐
LinkedIn
linkedin.com › pulse › pentesting-ethical-hacking-tool-series-flask-session-cookie-vanegas
Pentesting and Ethical Hacking Tool Series: Flask Session Cookie Decoder/Encoder/BruteForce
June 1, 2023 - Flask-Unsign and Flask Session Cookie Decoder/Encoder are two Python scripts that allow us to decode, encode, brute-force, and craft session cookies for a Flask application by guessing secret keys.
🌐
saruberoz' site
saruberoz.github.io › flask-session-cookie-decoder-slash-encoder
Flask session cookie manager – saruberoz' site
Use the session_cookie_encoder to setup a stub/mock session cookie data python session_cookie_manager.py <encode> <secret_key> <session_cookie_structure> ... """ Flask Session Cookie Decoder/Encoder """ __author__ = 'Wilson Sumanang' # standard imports import sys import zlib from itsdangerous import base64_decode # external Imports from flask.sessions import SecureCookieSessionInterface class MockApp(object): def __init__(self, secret_key): self.secret_key = secret_key def session_cookie_encoder(secret_key, session_cookie_structure): """ Encode a Flask session cookie Example: cookie_structure
🌐
Sneawo
blog.sneawo.com › blog › 2018 › 06 › 07 › how-to-decode-a-flask-session-or-a-csrf-token
How to decode a Flask session or a CSRF token - Andrey Zhukov's Tech Blog
June 07, 2018 flask, python · I’m using this example. The only change I made is return_timestamp=True parameter to find when the session was generated. import hashlib from itsdangerous import URLSafeTimedSerializer from flask.sessions import TaggedJSONSerializer def decode_session_cookie(secret_key, cookie_str): salt = 'cookie-session' serializer = TaggedJSONSerializer() signer_kwargs = { 'key_derivation': 'hmac', 'digest_method': hashlib.sha1 } s = URLSafeTimedSerializer(secret_key, salt=salt, serializer=serializer, signer_kwargs=signer_kwargs) return s.loads(cookie_str, return_timestamp=True) The same way it can be done for the csrf_token.
🌐
GitHub
gist.github.com › babldev › 502364a3f7c9bafaa6db
Decode a Flask Session cookie, given the cookie and secret key · GitHub
Decode a Flask Session cookie, given the cookie and secret key - decode_flask_cookie.py
🌐
Kali Linux
kalilinuxtutorials.com › home › kali linux › flask session cookie manager : flask session cookie decoder/encoder
Flask Session Cookie Manager : Flask Session Cookie Decoder/Encoder
August 19, 2020 - Usage: flask_session_cookie_manager.py decode [-h] [-s ] -c Optional Arguments: -h, –help show this help message and exit -s , –secret-key Secret key -c , –cookie-value Session cookie value ...
🌐
Ari
ari.lt › tools › flaskcookie
Tools - FlaskCookie - ari.lt
Decode Python Flask session cookies online and display their detailed information.
🌐
GitHub
github.com › rgcalsaverini › flask-session
GitHub - rgcalsaverini/flask-session: A tiny tool to decode, encode and brute-force flask sessions · GitHub
This is a tiny tool, service and chrome extension to decode, encode and brute-force flask sessions. ⚠️ This was created with the sole purpose of testing the security of my own applications, and should obviously not be used to attack or cause ...
Author   rgcalsaverini
🌐
Pentest Reports
pentestreports.com › tool › flask-session-cookie-decoderencoder
Flask Session Cookie Decoderencoder - Penetration Testing Command Reference Guide
A script that let you encode and decode a Flask session cookie · Source code · https://github.com/noraj/flask-session-cookie-manager · Language · Python · Price · Free · 0d1n · 1u.ms ·