| my rAnd0m m1ndfl0w |
| #whoami $bl0g /script.s retr0gaming |
Disobey 2023 - CTF - The Three Pass Method ------------------------------------------ Assignment here was: --snip-- 1: Alice creates a secret one-time pad, encrypts her message with it, and sends it to Bob: PEBVGMIKWVIKRQKWHVZCUQDVGVKTFIQKSMKEKXPWPETIPDEQWTKB 2: Bob receives the encrypted message, creates his own secret one-time pad, encrypts Alice's ciphertext with it, and sends it back to Alice: ILJNOEUIKIMDZCOLHYSJYHHVXZWTSGBSCQSXLRIPWMLWCHMIIBXF 3: Alice receives the doubly encrypted message, decrypts it with her own one-time pad, and sends it back to Bob: WLLMKAZEHUILMOVTTNXFMJXRZZUAYGQGYYAXFNAXWTSWAXMPFBBS 4: Bob receives the message, decrypts it with his own one-time pad, and can now read Alice's message. --snip-- This one is quite easy too, just figure out the cipher key between phases 1 and 2, then figure out the original cipher key Alice used by examining the cipher key between phases 2 and 3. After this you decrypt the original message with the key from first phase. I made an ugly Bash script out of this, as it was most likely one of the most absurd ways to go about it. Python, JS and almost anything else would've been more sane. Running this obscenity:
root@pwnb0x:$ bash threePassMethod.sh
Encrypted message:
PEBVGMIKWVIKRQKWHVZCUQDVGVKTFIQKSMKEKXPWPETIPDEQWTKB
|
'--> Encrypted with key 1:
THISISMYONETIMEPADTHEREAREMANYLIKEITBUTTHISONEISMINE
|
'--> Becomes:
ILJNOEUIKIMDZCOLHYSJYHHVXZWTSGBSCQSXLRIPWMLWCHMIIBXF
|
'--> Decrypted with key 2:
MAYBEEVEDOESNOTSOLVEMYKEYACTUALMESSAGEISATTACKATDAWN
|
'--> Becomes:
WLLMKAZEHUILMOVTTNXFMJXRZZUAYGQGYYAXFNAXWTSWAXMPFBBS
|
'--> Decrypted with key 1:
THISISMYONETIMEPADTHEREAREMANYLIKEITBUTTHISONEISMINE
|
'--> Becomes the original message:
DEDUCINGTHESECRETKEYISTRIVIALIFYOUSEETHEPLAINTEXTTOO
And the actual flag is already revealed on the second key: ....ACTUALMESSAGEISATTACKATDAWN So the flag was: ATTACKATDAWN |