login
masterkey
.temp_val=MD5(login+salt1+ masterkey)+ MD5(login+salt2+ masterkey)
temp_key=MD5(login+salt3+ masterkey)+ MD5(login+salt4+ masterkey)
TargetValue1=AES256_Encode(temp_key, temp_val)
TargetValue1
– AES256 ( , )TargetValue2
– Blowfish ( , )TargetValue3
– ( )TargetValue4
– ( )TargetValue1=46592074424B97EDFEBEB259A1B20390343C282C2D0B2154D5FF7E10BD0B5065
TargetValue2=721A6DD94327E53079D340CB563D94C389319262FA2E8F293BAD4EE4D2031B7D
TargetValue3=277567FD786E432F9762B33FDA8808A31933149573D1C84A8C1795CAC0FE6178
TargetValue4=DC7AF573B283F97017E91480611D9B0EFBF44F33AF0A03C8D00FA97DD7E16B4C
login, masterkey, temp_val, temp_key
.TargetValue3
TargetValue4
, wrong_login, .trash_from_server=C0ED5E324AD7DD3959493F4EFFE056C59AC6EC120C6123EF2D78A8202BF0F3F5A90BE8E0FE393C63B13D9CC95ADAC1DF8582B867220F5E2CCF416A23FDC22CE05C1BD0F5A7DE35D3C21BF2D0E4243348…..
( , !)tmp=Blowfish_Decode(TargetValue2,trash_from_server);
secret=AES256_Decode(TargetValue1,tmp);
alert(secret); // show bla-bla-bla :-)
Source: https://habr.com/ru/post/79997/
All Articles