Path: blob/master/attacks/ecb/plaintext_recovery_hardest.py
2589 views
def attack(encrypt_oracle, unused_byte=0):1"""2Recovers a secret which is appended to a plaintext and encrypted using ECB.3In this scenario, the encryption oracle prepends a random prefix (length 0 to 16) to the plaintext.4:param encrypt_oracle: the encryption oracle5:param unused_byte: a byte that's never used in the secret or random prefix6:return: the secret7"""8paddings = [bytes([unused_byte] * i) for i in range(16)]9prefix = bytes([unused_byte] * 32)10secret = bytearray()11while True:12padding = paddings[15 - (len(secret) % 16)]13p = bytearray(prefix + padding + secret + b"0" + padding)14byte_index = len(prefix) + len(padding) + len(secret)15end1 = len(prefix) + len(padding) + len(secret) + 116end2 = end1 + len(padding) + len(secret) + 117for i in range(256):18p[byte_index] = i19c = encrypt_oracle(p)20while c[0:16] != c[16:32]:21c = encrypt_oracle(p)2223if c[end1 - 16:end1] == c[end2 - 16:end2]:24secret.append(i)25break26else:27secret.pop()28break2930return bytes(secret)313233