CS / ITS PREPCOURSE · EXERCISE 03 · CRYPTOGRAPHY
Change the order.
Keep the key unknown.
The festival order is tickets=1. Can you make the receiver read tickets=9 by changing only encrypted bytes?
Offline experiment · fictional order · browser-generated keys
Your experiment
- Inspect the character and byte positions below. Change the encrypted byte corresponding to the digit.
- Make the XOR receiver accept
tickets=9, then try another single-digit count. - Try changing an encrypted byte in the authenticated version. Compare the receiver's response.
- Export your lab record. Keep the same experiment while comparing original and edited bytes.
This is a known-plaintext experiment: you know the original order, but the key is hidden in the interface. XOR combines individual bits: equal bits give 0; different bits give 1. Applying the same XOR value twice undoes the change.
1 / Encryption without an authenticity check
XOR teaching modelEach plaintext byte is XORed with one random secret key byte. Edit a ciphertext byte in the final row (hexadecimal, two digits).
Preparing experiment…
Offsets start at zero. Restoring bytes keeps the key; “New experiment” creates fresh keys.
Byte calculator
Combine up to three bytes with XOR. Enter hexadecimal values from 00 to ff.
31 XOR 39 = 08 (hex)
00110001 XOR 00111001 = 00001000
Why a character is not a number
The character 1 has ASCII byte value 31 in hexadecimal (49 in decimal). The character 9 has byte value 39 (57 in decimal).
Each hex digit represents four bits. A byte has eight bits, so we write it with two hex digits.
Hint 1 · Locate the digit
The digit is at offset 8, the ninth byte. Leave the other eight ciphertext bytes unchanged.
Hint 2 · Find the difference
XOR the old character byte with the desired character byte. Apply that difference to the original ciphertext byte.
Hint 3 · Complete formula
c′ = c XOR m XOR m′. For 1 → 9, XOR the original encrypted byte at offset 8 with 08. Use the calculator with the actual ciphertext byte.
2 / Encryption with an authenticity check
AES-GCM · Web CryptoThis independently encrypts the same order using AES-GCM. First send the original bytes, then change one ciphertext byte and submit again. The original nonce and authentication tag stay attached to the message.
Preparing authenticated encryption…
Inspect the message envelope
This experiment keeps the valid tag from the original message. The receiver verifies it during decryption. It does not compare your edit against a stored ciphertext.
GCM rejection shows failed authentication, not a decrypted order. Restoring the original bytes should allow the original order again.
Lab record
Each receiver submission adds a row below. Export before reloading; the notebook lives only in this page.
| Experiment | Mode | Submitted hex | Result | Note |
|---|
Bonus / Reused key stream
Open bonus/key-reuse.txt. Two messages were encrypted with the same XOR key stream, and one entire plaintext is known. Recover the second message. Implement the TODOs in bonus/starter.py to automate this and to replace known parts of ciphertext.
CyberChef offers byte conversion and XOR operations for further exploration. The supplied files require no external service.