Recognising encodings
Tell Base64 from hex from Base32 from binary on sight, peel layered encodings, and learn why an encoding is not encryption.
By the end you can
- Identify Base64, Base64-URL, hex, Base32, binary, and Morse from their alphabets alone
- Decode a multi-layer wrapper without guessing the order
- Explain why encoding provides no confidentiality
- Recognise when a decode produced bytes rather than text, and switch approach
- Read percent-encoding and HTML entities as transport artefacts rather than as the puzzle
1. Read
Spot the encoding: reading base64, base32, hex and friends at a glance
Alphabet, length, and padding are enough to name almost any encoding on sight. A field guide to the encodings CTFs actually use, the magic prefixes that tell you what is underneath, and the traps that make a correct guess look wrong.
The first ten minutes: a triage playbook for any CTF challenge
Most challenges are lost to flailing, not to difficulty. Here is a repeatable order of operations for an unknown blob, an unknown file, and an unknown service - and the point at which you should stop guessing and start reading.
2. Use the tools
In the order they come up while solving. Read what each one does, or go straight to the workspace tab that runs it.
- Cipher identifier and automatic decoder
Paste anything and find out what it is. ctfpal runs every decoder and rotation, including multi-pass cascades, and ranks results by English-likeness and flag patterns.
Open it in the workspace - Base64 decoder and encoder
Decode and encode Base64 and Base64-URL in the browser, with padding repair and automatic detection of nested encodings. Nothing is uploaded.
Open it in the workspace - Hex to text converter
Convert hexadecimal to text and back, tolerating whitespace, commas, and `0x` prefixes. Runs entirely in your browser.
Open it in the workspace - Base32 decoder and encoder
Decode Base32 (RFC 4648) to text or bytes, with padding repair. Distinguishes Base32 from Base64 and hex automatically.
Open it in the workspace - Binary to text converter
Convert binary (and decimal codepoints) to text and back. Handles 7-bit and 8-bit groupings, arbitrary separators, and reversed bit order.
Open it in the workspace - URL decoder and encoder
Percent-decode and encode URL components, including double-encoded payloads and `+`-as-space form encoding.
Open it in the workspace - HTML entity decoder
Decode named, decimal, and hexadecimal HTML entities back to text - including the mixed-form entities used to slip past XSS filters.
Open it in the workspace - ASCII table with hex, decimal, octal and binary
Every codepoint from 0 to 127 with its decimal, hexadecimal, octal, and binary representation and control-character name.
Open it in the workspace - Base58, UUID and colour utilities
Decode Base58 and Base58Check, inspect UUID versions and embedded timestamps, and convert colour notations.
Open it in the workspace - Recipe builder: chain decodes and transforms
Build a repeatable chain of operations - decode, decompress, XOR, decrypt - see the output after every step, and share the whole thing as a link.
Open it in the workspace
3. Try one now
Generated in your browser and checked in your browser. No account, nothing to download, and a fresh one whenever you want another.
4. Practise on the real thing
Real picoCTF challenges that use these techniques, easiest first. 59 match in total - see the full index.
Common mistakes
The wrong turns this topic reliably produces. Written as the mistake rather than the rule, because the rule is easy to agree with and easy to walk straight past.
- Running decoders in sequence until something looks like text. The alphabet identifies the format before anything is decoded, and being right first is the skill.
- Treating a trailing = as proof of Base64. Base32 pads the same way, and Base64-URL in tokens and query strings usually has no padding at all.
- Stopping at the first successful decode when the output is still high-entropy - that is normally another layer, or a cipher, not a dead end.
- Pasting the mojibake from one decode straight into the next tool. If the output has no printable structure it is probably a file, and its first four bytes will say which one before another decode wastes the turn.
- Counting percent-encoding or HTML entities as a layer of the puzzle. Both are added in transit by a browser or a template, so peeling them tells you how the string travelled rather than what the challenge hid.
Checkpoint
Given a three-layer encoded string, produce the plaintext and state each layer in order.
Teaching note
The instinct students arrive with is to try decoders at random until one works. The habit worth building instead is to look at the alphabet first and predict the format before decoding - being right is the point, not the answer.
Go deeper
The lessons above are written to get you through a challenge. These go after the subject instead. Each one opens our notes on that chapter - what it argues, what to take from it and where it stops - so this is somewhere to read now rather than a book to buy first. Nothing here is affiliate-linked or sold by us.
Chapter 5, Cryptography
Designing Secure Software - Loren Kohnfelder
Sets out what cryptography actually promises, which is the cleanest way to see that an encoding promises none of it.
Chapter 4, Exploring Datasets in the Terminal
Hacks, Leaks, and Revelations - Micah Lee
The same first move on a much larger scale: look at the bytes before deciding what a file is.
Chapter 3, Network Protocol Structures
Attacking Network Protocols - James Forshaw
Names the structures underneath an encoding - tag-length-value, variable-length fields, text versus binary framing - which is what you are really recognising.
Every book the curriculum cites has a page in the library.