updated sheesh

This commit is contained in:
lightningitoid
2025-10-27 08:26:11 +07:00
parent bbeb22211e
commit 6f7f8fc1e3
2 changed files with 106 additions and 108 deletions
+50 -51
View File
@@ -1,77 +1,80 @@
#!/usr/bin/env python3 #!/usr/bin/env python3
import os, sys, binascii, random import os, sys, signal, binascii, random
from Crypto.Cipher import AES from Crypto.Cipher import AES
from Crypto.Util.Padding import pad, unpad from Crypto.Util.Padding import pad, unpad
from Crypto.Util.number import bytes_to_long, long_to_bytes from Crypto.Util.number import bytes_to_long, long_to_bytes
random.seed(os.urandom(16)) random.seed(os.urandom(16))
k0 = os.urandom(16) K0 = os.urandom(16)
k1 = os.urandom(16) K1 = os.urandom(16)
s0 = os.urandom(16); S1 = os.urandom(16) S0 = os.urandom(16)
m0 = os.urandom(16); M1 = os.urandom(16) S1 = os.urandom(16)
M0 = os.urandom(16)
M1 = os.urandom(16)
with open("/flag.txt","rb") as f: with open("./flag.txt","rb") as f:
flag = f.read() flag = f.read()
def hex_input(q): def hex_input(q):
s = input(q).strip() s = input(q).strip()
try: return binascii.unhexlify(s) try: return binascii.unhexlify(s)
except: print("err"); return None except: print("err"); return None
def xex(b16): def enc1(b16: bytes) -> bytes:
x = AES.new(k1, AES.MODE_ECB).encrypt(b16) x = AES.new(K1, AES.MODE_ECB).encrypt(b16)
return bytes(a ^ b for a,b in zip(x, b16)) return bytes(a ^ b for a, b in zip(x, b16))
def enc1(iv, msg): def enc2(iv: bytes, m: bytes) -> bytes:
return AES.new(k0, AES.MODE_CBC, iv=iv).encrypt(pad(msg,16)) return AES.new(K0, AES.MODE_CBC, iv=iv).encrypt(pad(m, 16))
def dec1(iv, c): def enc3(m: bytes) -> bytes:
return unpad(AES.new(k0, AES.MODE_CBC, iv=iv).decrypt(c), 16) return AES.new(K1, AES.MODE_CBC, iv=b"\x00"*16).encrypt(pad(m, 16))[-16:]
def enc2(msg): def T(iv: bytes, ct: bytes):
return AES.new(k1, AES.MODE_CBC, iv=b"\x00"*16).encrypt(pad(msg,16))[-16:]
def F(iv, ct):
n = len(ct) n = len(ct)
if n < 96 or (n & 15): return None if n < 96 or (n & 15):
W = [ct[i:i+16] for i in range(0, n, 16)] return None
v = memoryview(ct)
W = [bytes(v[i:i+16]) for i in range(0, n, 16)]
m = len(W) m = len(W)
digest = enc2(iv) r = ((iv[0] & 7) + 2) % m
r = ((iv[0]^iv[-1]) & 7) + 2 if r:
r %= m W = W[r:] + W[:r]
if r: W = W[r:] + W[:r]
if len(W) < 3: return None j = 1 + (W[0][0] & 1)
A0 = long_to_bytes(bytes_to_long(W[0]) ^ bytes_to_long(m0)) if len(W) <= j:
A1 = long_to_bytes(bytes_to_long(W[1]) ^ bytes_to_long(M1)) return None
j = 1 + (digest[0] & 1)
del W[j] del W[j]
if len(W) < 2: return None if len(W) < 2:
return None
return b"".join((s0, A0, S1, A1, *W[2:])) a0 = long_to_bytes(bytes_to_long(W[0]) ^ bytes_to_long(M0))
a1 = long_to_bytes(bytes_to_long(W[1]) ^ bytes_to_long(M1))
return b"".join((S0, a0, S1, a1, *W[2:]))
def O(iv, ct): def C(iv: bytes, ct: bytes) -> bool:
z = F(iv, ct) z = T(iv, ct)
if z is None: if z is None:
ok = False ok = False
else: else:
try: try:
dec1(iv, z) x = AES.new(K0, AES.MODE_CBC, iv=iv).decrypt(z)
unpad(x, 16)
ok = True ok = True
except: except:
ok = False ok = False
if random.random() < 0.10: if random.random() < 0.08:
ok = not ok ok = not ok
return ok return ok
iv = os.urandom(16) iv = os.urandom(16)
MK = enc2(iv + iv) MK = enc3(iv + iv)
h0 = (flag + b"\x00"*16)[:16] H0 = (flag + b"\x00"*16)[:16]
h1 = bytes(a ^ b for a,b in zip(h0, MK)) H1 = bytes(a ^ b for a, b in zip(H0, MK))
pt = h1 + flag[16:] pt = H1 + flag[16:]
ct = enc1(iv, pt) ct = enc2(iv, pt)
print("iv:", iv.hex()) print("iv:", iv.hex())
print("ct:", ct.hex()) print("ct:", ct.hex())
@@ -79,21 +82,17 @@ print()
while True: while True:
try: try:
inp = hex_input("inp: ") blob = hex_input("blob: ")
if inp is None: if blob is None:
print("hmmm\n"); continue print("err\n"); continue
L = len(inp) L = len(blob)
if L == 16: if L == 16:
y = xex(inp) y = enc1(blob)
print("blk:", y.hex()); print() print("blk:", y.hex()); print()
elif L >= 32 and (L % 16) == 0: elif L >= 32 and (L % 16) == 0:
ivq, ctq = inp[:16], inp[16:] iv, ct = blob[:16], blob[16:]
print("ok\n" if O(ivq, ctq) else "zzz\n") print("ok\n" if C(iv, ct) else "no\n")
else: else:
print("hmmm\n") print("err\n")
except EOFError: except EOFError:
break break
+50 -51
View File
@@ -1,77 +1,80 @@
#!/usr/bin/env python3 #!/usr/bin/env python3
import os, sys, binascii, random import os, sys, signal, binascii, random
from Crypto.Cipher import AES from Crypto.Cipher import AES
from Crypto.Util.Padding import pad, unpad from Crypto.Util.Padding import pad, unpad
from Crypto.Util.number import bytes_to_long, long_to_bytes from Crypto.Util.number import bytes_to_long, long_to_bytes
random.seed(os.urandom(16)) random.seed(os.urandom(16))
k0 = os.urandom(16) K0 = os.urandom(16)
k1 = os.urandom(16) K1 = os.urandom(16)
s0 = os.urandom(16); S1 = os.urandom(16) S0 = os.urandom(16)
m0 = os.urandom(16); M1 = os.urandom(16) S1 = os.urandom(16)
M0 = os.urandom(16)
M1 = os.urandom(16)
with open("/flag.txt","rb") as f: with open("./flag.txt","rb") as f:
flag = f.read() flag = f.read()
def hex_input(q): def hex_input(q):
s = input(q).strip() s = input(q).strip()
try: return binascii.unhexlify(s) try: return binascii.unhexlify(s)
except: print("err"); return None except: print("err"); return None
def xex(b16): def enc1(b16: bytes) -> bytes:
x = AES.new(k1, AES.MODE_ECB).encrypt(b16) x = AES.new(K1, AES.MODE_ECB).encrypt(b16)
return bytes(a ^ b for a,b in zip(x, b16)) return bytes(a ^ b for a, b in zip(x, b16))
def enc1(iv, msg): def enc2(iv: bytes, m: bytes) -> bytes:
return AES.new(k0, AES.MODE_CBC, iv=iv).encrypt(pad(msg,16)) return AES.new(K0, AES.MODE_CBC, iv=iv).encrypt(pad(m, 16))
def dec1(iv, c): def enc3(m: bytes) -> bytes:
return unpad(AES.new(k0, AES.MODE_CBC, iv=iv).decrypt(c), 16) return AES.new(K1, AES.MODE_CBC, iv=b"\x00"*16).encrypt(pad(m, 16))[-16:]
def enc2(msg): def T(iv: bytes, ct: bytes):
return AES.new(k1, AES.MODE_CBC, iv=b"\x00"*16).encrypt(pad(msg,16))[-16:]
def F(iv, ct):
n = len(ct) n = len(ct)
if n < 96 or (n & 15): return None if n < 96 or (n & 15):
W = [ct[i:i+16] for i in range(0, n, 16)] return None
v = memoryview(ct)
W = [bytes(v[i:i+16]) for i in range(0, n, 16)]
m = len(W) m = len(W)
digest = enc2(iv) r = ((iv[0] & 7) + 2) % m
r = ((iv[0]^iv[-1]) & 7) + 2 if r:
r %= m W = W[r:] + W[:r]
if r: W = W[r:] + W[:r]
if len(W) < 3: return None j = 1 + (W[0][0] & 1)
A0 = long_to_bytes(bytes_to_long(W[0]) ^ bytes_to_long(m0)) if len(W) <= j:
A1 = long_to_bytes(bytes_to_long(W[1]) ^ bytes_to_long(M1)) return None
j = 1 + (digest[0] & 1)
del W[j] del W[j]
if len(W) < 2: return None if len(W) < 2:
return None
return b"".join((s0, A0, S1, A1, *W[2:])) a0 = long_to_bytes(bytes_to_long(W[0]) ^ bytes_to_long(M0))
a1 = long_to_bytes(bytes_to_long(W[1]) ^ bytes_to_long(M1))
return b"".join((S0, a0, S1, a1, *W[2:]))
def O(iv, ct): def C(iv: bytes, ct: bytes) -> bool:
z = F(iv, ct) z = T(iv, ct)
if z is None: if z is None:
ok = False ok = False
else: else:
try: try:
dec1(iv, z) x = AES.new(K0, AES.MODE_CBC, iv=iv).decrypt(z)
unpad(x, 16)
ok = True ok = True
except: except:
ok = False ok = False
if random.random() < 0.10: if random.random() < 0.08:
ok = not ok ok = not ok
return ok return ok
iv = os.urandom(16) iv = os.urandom(16)
MK = enc2(iv + iv) MK = enc3(iv + iv)
h0 = (flag + b"\x00"*16)[:16] H0 = (flag + b"\x00"*16)[:16]
h1 = bytes(a ^ b for a,b in zip(h0, MK)) H1 = bytes(a ^ b for a, b in zip(H0, MK))
pt = h1 + flag[16:] pt = H1 + flag[16:]
ct = enc1(iv, pt) ct = enc2(iv, pt)
print("iv:", iv.hex()) print("iv:", iv.hex())
print("ct:", ct.hex()) print("ct:", ct.hex())
@@ -79,21 +82,17 @@ print()
while True: while True:
try: try:
inp = hex_input("inp: ") blob = hex_input("blob: ")
if inp is None: if blob is None:
print("hmmm\n"); continue print("err\n"); continue
L = len(inp) L = len(blob)
if L == 16: if L == 16:
y = xex(inp) y = enc1(blob)
print("blk:", y.hex()); print() print("blk:", y.hex()); print()
elif L >= 32 and (L % 16) == 0: elif L >= 32 and (L % 16) == 0:
ivq, ctq = inp[:16], inp[16:] iv, ct = blob[:16], blob[16:]
print("ok\n" if O(ivq, ctq) else "zzz\n") print("ok\n" if C(iv, ct) else "no\n")
else: else:
print("hmmm\n") print("err\n")
except EOFError: except EOFError:
break break