4 ms·
>>> cb = bytes.fromhex('6968766f606e776c2d2d21262138475c5b5a475b545e475c6b6a776b646e776c6b6a772b646e776c6b6a776b646e776c6b6a776bbadf04036b6a776c616a846f') >>>
by terom 7y ago
>>> cb = bytes.fromhex('6968766f606e776c2d2d21262138475c5b5a475b545e475c6b6a776b646e776c6b6a772b646e776c6b6a776b646e776c6b6a776bbadf04036b6a776c616a846f')
>>> pb = b'\x02\x02\x01\x04\x04\x00\x00\x00FGVMEV0000000000\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00@\x00\x00\x00\x00\x00\x00...'
>>> print(''.join(chr(c ^ k) for c, k in zip(cb, pb)))
kjwkdnwlkjwkdnwlkjwkdnwlkjwkdnwlkjwkdnwlkjYEJ
EDIT: The repeating XOR key is pretty obvious. Just ignore the junk at the end from the `...` in the given plaintext.
- Scoundreller 7y agoKey looks more like they just bashed the home row with a few extensions of the longer fingers.
- segfaultbuserr 7y agoApparently, running "uuidgen" is too difficult for them. Which, shouldn't be a surprise for someone who already decided to use XOR "encryption".
- Koshkin 7y agoWouldn’t a random sequence using a seed as the secret be a better choice?
- userbinator 7y agoThat's called a "stream cipher". ;-)
- segfaultbuserr 7y agoYes. If you can build a cryptographically-secure random number generator, which can output a long stream of random bytes from a seed, congrats, you just invented a stream cipher. Just XOR your plaintext and random bytes, and you are good to go.
- zamalek 7y agoXOR encryption is unbreakable with an one-time pad that matches the message length (that's basically AES CTR). It's one of the most secure cryptography primitives we have. The problem is deciding to use home-grown encryption.
- tptacek 7y agoAES CTR isn't a one-time pad. It's as strong as AES, not theoretically unbreakable.
- zamalek 7y ago"Basically" is the key word there.
- loeg 7y agoThis isn't a one-time pad. It's reused for every message.
- herio 7y agoI usually say that encryption is the easy part. Just use XOR and you are good. All the complicated bits are related to key management.
- Thorrez 7y agoInteresting, kjwkdnwl hasn't been seen before in Have I Been Pwned.