Extracting Saved DBeaver Passwords as Plaintext
DBeaver stores database connection passwords locally with AES encryption. If you know the key, you can decrypt them.
Requirements
- Python 3
- The pycryptodome package
pip3 install pycryptodome
Script
Place the file under
~/Library/DBeaverData/workspace6and run it
#!/usr/bin/env python3
# NOTE : pip3 install pycryptodome
import sys
import base64
import os
import json
from Crypto.Cipher import AES
import glob
config_file_paths = glob.glob('./**/.dbeaver/credentials-config.json', recursive=True)
for filepath in config_file_paths:
print(filepath)
# AES decryption key (hardcoded DBeaver key)
PASSWORD_DECRYPTION_KEY = bytes([186, 187, 74, 159, 119, 74, 184, 83, 201, 108, 45, 101, 61, 254, 84, 74])
data = open(filepath, 'rb').read()
# CBC-mode decryption: first 16 bytes = IV
decryptor = AES.new(PASSWORD_DECRYPTION_KEY, AES.MODE_CBC, data[:16])
padded_output = decryptor.decrypt(data[16:])
output = padded_output.rstrip(padded_output[-1:])
try:
print(json.dumps(json.loads(output), indent=4, sort_keys=True))
except:
print(output)
How It Works
DBeaver stores connection information in credentials-config.json and encrypts it with AES-CBC.
- Encryption key: A fixed 16-byte key hardcoded in the source
- IV (initialization vector): The first 16 bytes of the file
- Decryption: AES-CBC-decrypt the remaining bytes with the key and IV
Because the key is hardcoded, credentials can be decrypted from any DBeaver installation.
Caution
Use this script only to recover your own DBeaver passwords. Applying it to someone else's system without authorization is illegal.