CTF Write-up · Cryptography
Postbase
Recovering a corrupted Base64 prefix by enumerating the unknown leading characters against a known plaintext marker.
Challenge
The challenge supplies a string of letters and numbers and states only that it is not understood. The leading characters of the string are corrupted:
R[corrupted]BR3tCNDUzXzYxWDdZXzRSfQ==
Analysis
The trailing == padding and the restricted character set identify the data as Base64. The suffix is intact, but the first characters are unknown, so a direct decode fails. The decisive observation is that the plaintext is expected to begin with the token FLAG. This converts an unknown-prefix problem into a bounded search.
Solution
Candidate strings matching the known pattern are generated with exrex, each is decoded, and the single candidate whose decoded output begins with FLAG is accepted.
#!/usr/bin/env python3
import base64, exrex
def Base64_D(base64_message):
message = base64.b64decode(base64_message.encode('ascii')).decode('ascii')
if message[:4].upper() == "FLAG":
print(message)
if __name__ == "__main__":
B64hash = exrex.generate('R([A-Za-z0-9+])+BR3tCNDUzXzYxWDdZXzRSfQ==')
for i in B64hash:
try:
Base64_D(str(i))
except Exception:
pass
The candidate that decodes to a string beginning with FLAG is the flag.