Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Encrypted documents

Every read command takes --password, and Document takes password=:

docboss text locked.docx --password secret
docboss convert locked.docx --password secret -o unlocked.docx
import docboss

doc = docboss.Document("locked.docx", password="secret")
print(doc.extract_text())

What opens:

  • DOCX protected with a password to open is an OLE compound file holding EncryptionInfo and EncryptedPackage streams ([MS-OFFCRYPTO]). docboss decrypts Agile encryption (AES-128 or AES-256 in CBC mode, SHA-1 or SHA-512 key derivation with the spin count, the data-integrity HMAC checked) and Standard encryption (AES-128 in ECB mode, SHA-1), then reads the package like any other. Word 2007 to 2013 and LibreOffice files open.
  • DOC with RC4 or RC4 CryptoAPI encryption ([MS-DOC] with the [MS-OFFCRYPTO] key derivations), or with XOR obfuscation (the password verifier and XOR array of [MS-OFFCRYPTO] method 2; the password is tried in the document's code page and by the low byte of each character, as the specification asks).

A wrong password is an error that says so; a tampered Agile package fails its integrity check. Password-protected Word 6 and Word 95 files are refused with an error.

convert writes the decrypted document as a plain, unencrypted DOCX; there is no way to write an encrypted one yet.