Path: blob/master/attacks/ecb/plaintext_recovery.py
2589 views
def attack(encrypt_oracle, unused_byte=0):1"""2Recovers a secret which is appended to a plaintext and encrypted using ECB.3:param encrypt_oracle: the encryption oracle4:param unused_byte: a byte that's never used in the secret5:return: the secret6"""7paddings = [bytes([unused_byte] * i) for i in range(16)]8secret = bytearray()9while True:10padding = paddings[15 - (len(secret) % 16)]11p = bytearray(padding + secret + b"0" + padding)12byte_index = len(padding) + len(secret)13end1 = len(padding) + len(secret) + 114end2 = end1 + len(padding) + len(secret) + 115for i in range(256):16p[byte_index] = i17c = encrypt_oracle(p)18if c[end1 - 16:end1] == c[end2 - 16:end2]:19secret.append(i)20break21else:22secret.pop()23break2425return bytes(secret)262728