Skip to main content

A small Python library for decoding ASP.NET viewstate.

Viewstate is a method used in the ASP.NET framework to persist changes to a web form across postbacks. It is usually saved on a hidden form field:

<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEP...">

Decoding the view state can be useful in penetration testing on ASP.NET applications, as well as revealing more information that can be used to efficiently scrape web pages.

https://github.com/yuvadm/viewstate/workflows/Build/badge.svg https://img.shields.io/pypi/v/viewstate

Install

$ pip install viewstate

Usage

The Viewstate decoder accepts Base64 encoded .NET viewstate data and returns the decoded output in the form of plain Python objects.

There are two main ways to use this package. First, it can be used as an imported library with the following typical use case:

>>> from viewstate import ViewState
>>> base64_encoded_viewstate = '/wEPBQVhYmNkZQ9nAgE='
>>> vs = ViewState(base64_encoded_viewstate)
>>> vs.decode()
('abcde', (True, 1))

It is also possible to feed the raw bytes directly:

>>> vs = ViewState(raw=b'\xff\x01....')

Alternatively, the library can be used via command line by directly executing the module:

$ cat data.base64 | python -m viewstate

Which will pretty-print the decoded data structure.

The command line usage can also accept raw bytes with the -r flag:

$ cat data.base64 | base64 -d | python -m viewstate -r

Viewstate HMAC signatures are also supported. In case there are any remaining bytes after parsing, they are assumed to be HMAC signatures, with the types estimated according to signature length.

>>> vs = ViewState(signed_view_state)
>>> vs.decode()
>>> vs.mac
'hmac_sha256'
>>> vs.signature
b'....'

Development

Development packages can be installed with uv. Unit tests, lints and code formatting tasks can be run with:

$ uv sync --group dev
$ uv run pytest
$ uv run ruff

For PyPI releases, run build and publish:

$ uv build
$ uv publish

Note that for uploading a new package version, a valid PyPI auth token should be configured.

References

Since there is no publically available specification of how .NET viewstate is encoded, reverse engineering was based on prior work:

Any official documents would be gladly accepted to help improve the parsing logic.

License

MIT

Metadata

Release files for viewstate 0.7.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for viewstate 0.7.0
File Size Uploaded
viewstate-0.7.0.tar.gz 8.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for viewstate 0.7.0
File Interpreter ABI Platform
viewstate-0.7.0-py3-none-any.whl Python 3 none any Details

Total release size: 16.4 kB

Release files / viewstate-0.7.0.tar.gz

Download URL viewstate-0.7.0.tar.gz
Size 8.9 kB
Tags Source
SHA-256 checksum
How to use checksums
6544ee05b528ecc2885627c55f10e32b7dfe3e1b71a4ecffb000c455dae8dee4
BLAKE2b-256 checksum
How to use checksums
81ab0909fc024e69e41ae6bbb08c651c9ad495f79b00390625886d7cd1a5aed6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.6.14

Release files / viewstate-0.7.0-py3-none-any.whl

Download URL viewstate-0.7.0-py3-none-any.whl
Size 7.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
3d46bddd7832f80f7e5852b0c65c26dcf81b90069cc836ec4cd881addeb07d49
BLAKE2b-256 checksum
How to use checksums
488da172fb533625a40ad5d9183784d46077abd64b0e395683ac6e23d524be7b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.6.14

Release history Release notifications | RSS feed

This release

0.7.0 This release

2 release files

0.6.0

2 release files

0.5.3

1 release file

0.5.2

1 release file

0.5.1

1 release file

0.4.3

2 release files

0.4.2

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.1

1 release file

0.2.0

1 release file

0.1.2

1 release file

0.1.1

1 release file

0.1.0

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page