Skip to content

Lesson pack 1 · Foundation · 60 minutes

Recognising encodings

Tell Base64 from hex from Base32 from binary on sight, peel layered encodings, and learn why an encoding is not encryption.

Print this page for a paper plan - the navigation and links drop out.Student-facing version

Before the session

  • Nothing to install. Students need a browser and https://ctfpal.com. Confirm the room can reach it once; after that it works offline.
  • Read the lesson yourself first - about 14 minutes.
  • Have one worked example ready to paste. The classroom link builder on the instructor page turns it into a URL that opens preloaded.

Objectives

Written as things a student can do afterwards, so they can be assessed rather than asserted.

  1. Identify Base64, Base64-URL, hex, Base32, binary, and Morse from their alphabets alone
  2. Decode a multi-layer wrapper without guessing the order
  3. Explain why encoding provides no confidentiality
  4. Recognise when a decode produced bytes rather than text, and switch approach
  5. Read percent-encoding and HTML entities as transport artefacts rather than as the puzzle

Running order (60 min)

TimeWhat happens
0:00-0:06Frame the problemWhat the category looks like when you meet it cold, and why the naive approach fails.
0:06-0:18Teach the methodThe technique itself, on the board or from the lesson. No tools open yet.
0:18-0:33Demonstrate liveSame technique, in the workspace, on your worked example. Narrate every choice.
0:33-0:54Practice setStudents work the challenges. Circulate rather than present.
0:54-1:00Checkpoint and wrapCollect the artefact, name what comes next.

Tools used

  • Cipher identifier and automatic decoder - Paste anything and find out what it is. ctfpal runs every decoder and rotation, including multi-pass cascades, and ranks results by English-likeness and flag patterns.https://ctfpal.com/?tool=cipher-identifier
  • Base64 decoder and encoder - Decode and encode Base64 and Base64-URL in the browser, with padding repair and automatic detection of nested encodings. Nothing is uploaded.https://ctfpal.com/?tool=base64-decoder
  • Hex to text converter - Convert hexadecimal to text and back, tolerating whitespace, commas, and `0x` prefixes. Runs entirely in your browser.https://ctfpal.com/?tool=hex-decoder
  • Base32 decoder and encoder - Decode Base32 (RFC 4648) to text or bytes, with padding repair. Distinguishes Base32 from Base64 and hex automatically.https://ctfpal.com/?tool=base32-decoder
  • Binary to text converter - Convert binary (and decimal codepoints) to text and back. Handles 7-bit and 8-bit groupings, arbitrary separators, and reversed bit order.https://ctfpal.com/?tool=binary-to-text
  • URL decoder and encoder - Percent-decode and encode URL components, including double-encoded payloads and `+`-as-space form encoding.https://ctfpal.com/?tool=url-decoder
  • HTML entity decoder - Decode named, decimal, and hexadecimal HTML entities back to text - including the mixed-form entities used to slip past XSS filters.https://ctfpal.com/?tool=html-entity-decoder
  • ASCII table with hex, decimal, octal and binary - Every codepoint from 0 to 127 with its decimal, hexadecimal, octal, and binary representation and control-character name.https://ctfpal.com/?tool=ascii-table
  • Base58, UUID and colour utilities - Decode Base58 and Base58Check, inspect UUID versions and embedded timestamps, and convert colour notations.https://ctfpal.com/?tool=base58-uuid-utilities
  • Recipe builder: chain decodes and transforms - Build a repeatable chain of operations - decode, decompress, XOR, decrypt - see the output after every step, and share the whole thing as a link.https://ctfpal.com/?tool=recipe-builder

Reading

Practice set

Real picoCTF challenges tagged with this module’s techniques, easiest first. Assign the first three in class and the rest as homework.

  1. 2Warm - picoCTF 2019, easy
  2. Bases - picoCTF 2019, easy
  3. Binary Digits - picoCTF 2026, easy
  4. bytemancy 0 - picoCTF 2026, easy
  5. bytemancy 1 - picoCTF 2026, easy
  6. Codebook - Beginner picoMini 2022, easy
  7. ASCII FTW - picoGym Exclusive, medium
  8. ASCII Numbers - picoGym Exclusive, medium
  9. Based - picoCTF 2019, medium
  10. investigation_encoded_1 - picoCTF 2019, hard
  11. investigation_encoded_2 - picoCTF 2019, hard
  12. Investigative Reversing 0 - picoCTF 2019, hard

Checkpoint (gradeable)

Given a three-layer encoded string, produce the plaintext and state each layer in order.

Deliberately a produced artefact rather than a quiz question: it is either there or it is not, which makes it fast to mark and hard to bluff. Every tool in ctfpal is deterministic, so two students who did the work correctly hand in the same value.

Where the room gets stuck

The instinct students arrive with is to try decoders at random until one works. The habit worth building instead is to look at the alphabet first and predict the format before decoding - being right is the point, not the answer.

  • Running decoders in sequence until something looks like text. The alphabet identifies the format before anything is decoded, and being right first is the skill.
  • Treating a trailing = as proof of Base64. Base32 pads the same way, and Base64-URL in tokens and query strings usually has no padding at all.
  • Stopping at the first successful decode when the output is still high-entropy - that is normally another layer, or a cipher, not a dead end.
  • Pasting the mojibake from one decode straight into the next tool. If the output has no printable structure it is probably a file, and its first four bytes will say which one before another decode wastes the turn.
  • Counting percent-encoding or HTML entities as a layer of the puzzle. Both are added in transit by a browser or a template, so peeling them tells you how the string travelled rather than what the challenge hid.

If a student wants the subject, not the answer

Chapter-level references, so a student can be pointed at twenty pages rather than at a book. Nothing here is required to complete the module.

  • Designing Secure Software, Loren Kohnfelder. Chapter 5, Cryptography. Sets out what cryptography actually promises, which is the cleanest way to see that an encoding promises none of it.
  • Hacks, Leaks, and Revelations, Micah Lee. Chapter 4, Exploring Datasets in the Terminal. The same first move on a much larger scale: look at the bytes before deciding what a file is.
  • Attacking Network Protocols, James Forshaw. Chapter 3, Network Protocol Structures. Names the structures underneath an encoding - tag-length-value, variable-length fields, text versus binary framing - which is what you are really recognising.

If you finish early

  • Hand out a challenge from the cross-CTF index in this category - each one has published solutions to compare afterwards.
  • Run the same input through Identify and let the class argue with the ranking. Disagreeing with a confidence score is where the technique actually lands.
  • Ask a student to break their own example - construct an input that defeats the tool, and explain why.

Take this into a room

Markdown files, built here in your browser. They print, they open in anything, and they carry the challenge text - so the session works with no network in the room.