All write-ups

CTF Write-up · Cryptography

Postbase

Recovering a corrupted Base64 prefix by enumerating the unknown leading characters against a known plaintext marker.

Source: Cybertalents Category: Cryptography 50 points Easy

Challenge

The challenge supplies a string of letters and numbers and states only that it is not understood. The leading characters of the string are corrupted:

R[corrupted]BR3tCNDUzXzYxWDdZXzRSfQ==

Analysis

The trailing == padding and the restricted character set identify the data as Base64. The suffix is intact, but the first characters are unknown, so a direct decode fails. The decisive observation is that the plaintext is expected to begin with the token FLAG. This converts an unknown-prefix problem into a bounded search.

Solution

Candidate strings matching the known pattern are generated with exrex, each is decoded, and the single candidate whose decoded output begins with FLAG is accepted.

#!/usr/bin/env python3
import base64, exrex

def Base64_D(base64_message):
    message = base64.b64decode(base64_message.encode('ascii')).decode('ascii')
    if message[:4].upper() == "FLAG":
        print(message)

if __name__ == "__main__":
    B64hash = exrex.generate('R([A-Za-z0-9+])+BR3tCNDUzXzYxWDdZXzRSfQ==')
    for i in B64hash:
        try:
            Base64_D(str(i))
        except Exception:
            pass

The candidate that decodes to a string beginning with FLAG is the flag.

← Back to all write-ups