# Repository: moonD4rk/HackBrowserData # Stars: 13688 ## CLAUDE.md # CLAUDE.md This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository. ## Security Notice This project is for security research and defensive purposes only. Do not generate code that could be used for unauthorized access. All security research must be conducted ethically and within legal boundaries. ## Project Overview HackBrowserData is a CLI security research tool for extracting and decrypting browser data across Windows, macOS, and Linux. It supports Chromium-based browsers and Firefox. **Constraint**: Must build with Go 1.20 (Windows 7 support). Do not use features from Go 1.21+ (e.g., `log/slog`, `slices`, `maps`, `cmp` packages). ## Development Commands ```bash # Build (use go@1.20 for module operations) go build ./cmd/hack-browser-data/ # Cross-compile GOOS=windows GOARCH=amd64 go build ./cmd/hack-browser-data/ GOOS=linux GOARCH=amd64 go build ./cmd/hack-browser-data/ # Test go test ./... go test -v ./... -covermode=count -coverprofile=coverage.out # Lint (requires golangci-lint v2) golangci-lint run # Format (gofumpt is stricter than gofmt) gofumpt -l -w . goimports -w -local github.com/moond4rk/hackbrowserdata . # Spelling typos # Dependencies (MUST use go@1.20 to avoid bumping go directive) # export GOROOT=$(brew --prefix go@1.20)/libexec && export PATH=$GOROOT/bin:$PATH go mod tidy go mod verify ``` ## Code Conventions - **Platform code**: use build tags (`_darwin.go`, `_windows.go`, `_linux.go`) - **Error handling**: `fmt.Errorf("context: %w", err)` for wrapping, never `_ =` to ignore errors - **Logging**: `log.Debugf` for record-level diagnostics, `log.Infof` for user-facing progress/status, `log.Warnf` for unexpected conditions. Extract methods should return errors, not log them. - **Naming**: follow Go conventions — `Config` not `BrowserConfig`, `Extract` not `BrowsingData` - **Tests**: use `t.TempDir()` for filesystem tests, `go-sqlmock` for database tests - **Architecture**: see `rfcs/` for design documents ## Key Constraints - `modernc.org/sqlite` pinned at v1.31.1 (v1.32+ requires Go 1.21) - `golang.org/x/text` will be removed in refactoring (use 3-byte UTF-8 BOM instead) - No `pkg/` + `internal/` directory structure — keep it simple - No root-level library API — CLI calls `browser.PickBrowsers()` directly ## README.md
hack-browser-data logo
# HackBrowserData [![Lint](https://github.com/moonD4rk/HackBrowserData/actions/workflows/lint.yml/badge.svg)](https://github.com/moonD4rk/HackBrowserData/actions/workflows/lint.yml) [![Build](https://github.com/moonD4rk/HackBrowserData/actions/workflows/build.yml/badge.svg)](https://github.com/moonD4rk/HackBrowserData/actions/workflows/build.yml) [![Release](https://github.com/moonD4rk/HackBrowserData/actions/workflows/release.yml/badge.svg)](https://github.com/moonD4rk/HackBrowserData/actions/workflows/release.yml) [![Tests](https://github.com/moonD4rk/HackBrowserData/actions/workflows/test.yml/badge.svg?branch=main)](https://github.com/moonD4rk/HackBrowserData/actions/workflows/test.yml) [![codecov](https://codecov.io/gh/moonD4rk/HackBrowserData/branch/main/graph/badge.svg?token=KWJCN38657)](https://codecov.io/gh/moonD4rk/HackBrowserData) `HackBrowserData` is a command-line tool for decrypting and exporting browser data (passwords, history, cookies, bookmarks, credit cards, download history, localStorage, sessionStorage and extensions) from the browser. It supports the most popular browsers on the market and runs on Windows, macOS and Linux. > Disclaimer: This tool is only intended for security research. Users are responsible for all legal and related liabilities resulting from the use of this tool. The original author does not assume any legal responsibility. ## Supported Data Categories | Category | Chromium-based | Firefox | |:---------------|:--------------:|:-------:| | Password | ✅ | ✅ | | Cookie | ✅ | ✅ | | Bookmark | ✅ | ✅ | | History | ✅ | ✅ | | Download | ✅ | ✅ | | Credit Card | ✅ | - | | Extension | ✅ | ✅ | | LocalStorage | ✅ | ✅ | | SessionStorage | ✅ | - | ## Supported Browsers > On macOS, some Chromium-based browsers **require a current user password** to decrypt. | Browser | Windows | macOS | Linux | |:---------------|:-------:|:-----:|:-----:| | Chrome | ✅ | ✅ | ✅ | | Chrome Beta | ✅ | ✅ | ✅ | | Chromium | ✅ | ✅ | ✅ | | Edge | ✅ | ✅ | ✅ | | Brave | ✅ | ✅ | ✅ | | Opera | ✅ | ✅ | ✅ | | OperaGX | ✅ | ✅ | - | | Vivaldi | ✅ | ✅ | ✅ | | Yandex | ✅ | ✅ | - | | CocCoc | ✅ | ✅ | - | | Arc | - | ✅ | - | | QQ | ✅ | - | - | | 360 ChromeX | ✅ | - | - | | 360 Chrome | ✅ | - | - | | DC Browser | ✅ | - | - | | Sogou Explorer | ✅ | - | - | | Firefox | ✅ | ✅ | ✅ | ## Getting Started ### Install Installation of `HackBrowserData` is dead-simple, just download [the release for your system](https://github.com/moonD4rk/HackBrowserData/releases) and run the binary. You can also install via [Homebrew](https://brew.sh/): ```bash brew install moonD4rk/tap/hack-browser-data ``` > In some situations, this security tool will be treated as a virus by Windows Defender or other antivirus software and can not be executed. The code is all open source, you can modify and compile by yourself. ### Building from source Requires `Go 1.20+`. ```bash git clone https://github.com/moonD4rk/HackBrowserData cd HackBrowserData go build ./cmd/hack-browser-data/ ``` ### Cross-platform build ```bash # For Windows GOOS=windows GOARCH=amd64 go build ./cmd/hack-browser-data/ # For Linux GOOS=linux GOARCH=amd64 go build ./cmd/hack-browser-data/ ``` ## Usage ``` $ hack-browser-data -h hack-browser-data decrypts and exports browser data from Chromium-based browsers and Firefox on Windows, macOS, and Linux. GitHub: https://github.com/moonD4rk/HackBrowserData Usage: hack-browser-data [flags] hack-browser-data [command] Available Commands: dump Extract and decrypt browser data (default command) help Help about any command list List detected browsers and profiles version Print version information Flags: -b, --browser string target browser: all|chrome|firefox|edge|... (default "all") -c, --category string data categories (comma-separated): all|password,cookie,... (default "all") -d, --dir string output directory (default "results") -f, --format string output format: csv|json|cookie-editor (default "csv") -h, --help help for hack-browser-data --keychain-pw string macOS keychain password -p, --profile-path string custom profile dir path, get with chrome://version -v, --verbose enable debug logging --zip compress output to zip Use "hack-browser-data [command] --help" for more information about a command. ``` ### `dump` - Extract and decrypt browser data (default) Running `hack-browser-data` without a subcommand defaults to `dump`. | Flag | Short | Default | Description | |------------------|-------|-----------|--------------------------------------------------------------------------------------------------------------------------------------------| | `--browser` | `-b` | `all` | Target browser (all\|chrome\|firefox\|edge\|...) | | `--category` | `-c` | `all` | Data categories, comma-separated (all\|password\|cookie\|bookmark\|history\|download\|creditcard\|extension\|localstorage\|sessionstorage) | | `--format` | `-f` | `csv` | Output format (csv\|json\|cookie-editor) | | `--dir` | `-d` | `results` | Output directory | | `--profile-path` | `-p` | | Custom profile dir path, get with chrome://version | | `--keychain-pw` | | | macOS keychain password | | `--zip` | | `false` | Compress output to zip | ### `list` - List detected browsers and profiles | Flag | Default | Description | |------------|---------|--------------------------------| | `--detail` | `false` | Show per-category entry counts | ### `version` - Print version information ```bash hack-browser-data version ``` ### Global flags | Flag | Short | Description | |-------------|-------|----------------------| | `--verbose` | `-v` | Enable debug logging | ### Examples ```bash # Extract all data from all browsers (default) hack-browser-data # Extract specific browser and categories hack-browser-data dump -b chrome -c password,cookie # Export in JSON format to a custom directory hack-browser-data dump -b chrome -f json -d output # Export cookies in CookieEditor format hack-browser-data dump -f cookie-editor # Compress output to zip hack-browser-data dump --zip # List detected browsers and profiles hack-browser-data list # List with per-category entry counts hack-browser-data list --detail # Use custom profile path hack-browser-data dump -b chrome -p "/path/to/User Data/Default" ``` ## Contributing We welcome and appreciate any contributions made by the community (GitHub issues/pull requests, email feedback, etc.). Please see the [Contribution Guide](CONTRIBUTING.md) before contributing. ## Contributors
moonD4rk
Roger
Aquilao
Aquilao Official
uinfziuna8n
uinfziuna8n
VMpc
Cyrus
stevenlele
stevenlele
camandel
Carlo Mandelli
slimwang
slimwang
Amir-78
Amir.
a-urth
a-urth
dexhek
Ciprian Conache
SantiiRepair
Santiago Ramirez
BeichenDream
beichen
testwill
guoguangwu
zhe6652
zhe6652
lc6464
LC
mirefly
mirefly
slark-yuxj
YuXJ
ac0d3r
zznQ
## Stargazers over time [![Star History Chart](https://api.star-history.com/svg?repos=moond4rk/hackbrowserdata&type=Date)](https://github.com/moond4rk/HackBrowserData) ## 404StarLink 2.0 - Galaxy `HackBrowserData` is a part of 404Team [StarLink-Galaxy](https://github.com/knownsec/404StarLink2.0-Galaxy), if you have any questions about `HackBrowserData` or want to find a partner to communicate with, please refer to the [Starlink group](https://github.com/knownsec/404StarLink2.0-Galaxy#community). ## JetBrains OS licenses `HackBrowserData` had been being developed with `GoLand` IDE under the **free JetBrains Open Source license(s)** granted by JetBrains s.r.o., hence I would like to express my thanks here.