Lesson pack 1 · Foundation · 60 minutes
Recognising encodings
Tell Base64 from hex from Base32 from binary on sight, peel layered encodings, and learn why an encoding is not encryption.
Print this page for a paper plan - the navigation and links drop out.Student-facing version
Before the session
- Nothing to install. Students need a browser and https://ctfpal.com. Confirm the room can reach it once; after that it works offline.
- Read the lesson yourself first - about 14 minutes.
- Have one worked example ready to paste. The classroom link builder on the instructor page turns it into a URL that opens preloaded.
Objectives
Written as things a student can do afterwards, so they can be assessed rather than asserted.
- Identify Base64, Base64-URL, hex, Base32, binary, and Morse from their alphabets alone
- Decode a multi-layer wrapper without guessing the order
- Explain why encoding provides no confidentiality
- Recognise when a decode produced bytes rather than text, and switch approach
- Read percent-encoding and HTML entities as transport artefacts rather than as the puzzle
Running order (60 min)
| Time | What happens |
|---|---|
| 0:00-0:06 | Frame the problemWhat the category looks like when you meet it cold, and why the naive approach fails. |
| 0:06-0:18 | Teach the methodThe technique itself, on the board or from the lesson. No tools open yet. |
| 0:18-0:33 | Demonstrate liveSame technique, in the workspace, on your worked example. Narrate every choice. |
| 0:33-0:54 | Practice setStudents work the challenges. Circulate rather than present. |
| 0:54-1:00 | Checkpoint and wrapCollect the artefact, name what comes next. |
Tools used
- Cipher identifier and automatic decoder - Paste anything and find out what it is. ctfpal runs every decoder and rotation, including multi-pass cascades, and ranks results by English-likeness and flag patterns.https://ctfpal.com/?tool=cipher-identifier
- Base64 decoder and encoder - Decode and encode Base64 and Base64-URL in the browser, with padding repair and automatic detection of nested encodings. Nothing is uploaded.https://ctfpal.com/?tool=base64-decoder
- Hex to text converter - Convert hexadecimal to text and back, tolerating whitespace, commas, and `0x` prefixes. Runs entirely in your browser.https://ctfpal.com/?tool=hex-decoder
- Base32 decoder and encoder - Decode Base32 (RFC 4648) to text or bytes, with padding repair. Distinguishes Base32 from Base64 and hex automatically.https://ctfpal.com/?tool=base32-decoder
- Binary to text converter - Convert binary (and decimal codepoints) to text and back. Handles 7-bit and 8-bit groupings, arbitrary separators, and reversed bit order.https://ctfpal.com/?tool=binary-to-text
- URL decoder and encoder - Percent-decode and encode URL components, including double-encoded payloads and `+`-as-space form encoding.https://ctfpal.com/?tool=url-decoder
- HTML entity decoder - Decode named, decimal, and hexadecimal HTML entities back to text - including the mixed-form entities used to slip past XSS filters.https://ctfpal.com/?tool=html-entity-decoder
- ASCII table with hex, decimal, octal and binary - Every codepoint from 0 to 127 with its decimal, hexadecimal, octal, and binary representation and control-character name.https://ctfpal.com/?tool=ascii-table
- Base58, UUID and colour utilities - Decode Base58 and Base58Check, inspect UUID versions and embedded timestamps, and convert colour notations.https://ctfpal.com/?tool=base58-uuid-utilities
- Recipe builder: chain decodes and transforms - Build a repeatable chain of operations - decode, decompress, XOR, decrypt - see the output after every step, and share the whole thing as a link.https://ctfpal.com/?tool=recipe-builder
Reading
- Spot the encoding: reading base64, base32, hex and friends at a glance - 6 min. Alphabet, length, and padding are enough to name almost any encoding on sight. A field guide to the encodings CTFs actually use, the magic prefixes that tell you what is underneath, and the traps that make a correct guess look wrong.
- The first ten minutes: a triage playbook for any CTF challenge - 8 min. Most challenges are lost to flailing, not to difficulty. Here is a repeatable order of operations for an unknown blob, an unknown file, and an unknown service - and the point at which you should stop guessing and start reading.
Practice set
Real picoCTF challenges tagged with this module’s techniques, easiest first. Assign the first three in class and the rest as homework.
- 2Warm - picoCTF 2019, easy
- Bases - picoCTF 2019, easy
- Binary Digits - picoCTF 2026, easy
- bytemancy 0 - picoCTF 2026, easy
- bytemancy 1 - picoCTF 2026, easy
- Codebook - Beginner picoMini 2022, easy
- ASCII FTW - picoGym Exclusive, medium
- ASCII Numbers - picoGym Exclusive, medium
- Based - picoCTF 2019, medium
- investigation_encoded_1 - picoCTF 2019, hard
- investigation_encoded_2 - picoCTF 2019, hard
- Investigative Reversing 0 - picoCTF 2019, hard
Checkpoint (gradeable)
Given a three-layer encoded string, produce the plaintext and state each layer in order.
Deliberately a produced artefact rather than a quiz question: it is either there or it is not, which makes it fast to mark and hard to bluff. Every tool in ctfpal is deterministic, so two students who did the work correctly hand in the same value.
Where the room gets stuck
The instinct students arrive with is to try decoders at random until one works. The habit worth building instead is to look at the alphabet first and predict the format before decoding - being right is the point, not the answer.
- Running decoders in sequence until something looks like text. The alphabet identifies the format before anything is decoded, and being right first is the skill.
- Treating a trailing = as proof of Base64. Base32 pads the same way, and Base64-URL in tokens and query strings usually has no padding at all.
- Stopping at the first successful decode when the output is still high-entropy - that is normally another layer, or a cipher, not a dead end.
- Pasting the mojibake from one decode straight into the next tool. If the output has no printable structure it is probably a file, and its first four bytes will say which one before another decode wastes the turn.
- Counting percent-encoding or HTML entities as a layer of the puzzle. Both are added in transit by a browser or a template, so peeling them tells you how the string travelled rather than what the challenge hid.
If a student wants the subject, not the answer
Chapter-level references, so a student can be pointed at twenty pages rather than at a book. Nothing here is required to complete the module.
- Designing Secure Software, Loren Kohnfelder. Chapter 5, Cryptography. Sets out what cryptography actually promises, which is the cleanest way to see that an encoding promises none of it.
- Hacks, Leaks, and Revelations, Micah Lee. Chapter 4, Exploring Datasets in the Terminal. The same first move on a much larger scale: look at the bytes before deciding what a file is.
- Attacking Network Protocols, James Forshaw. Chapter 3, Network Protocol Structures. Names the structures underneath an encoding - tag-length-value, variable-length fields, text versus binary framing - which is what you are really recognising.
If you finish early
- Hand out a challenge from the cross-CTF index in this category - each one has published solutions to compare afterwards.
- Run the same input through Identify and let the class argue with the ranking. Disagreeing with a confidence score is where the technique actually lands.
- Ask a student to break their own example - construct an input that defeats the tool, and explain why.
Take this into a room
Markdown files, built here in your browser. They print, they open in anything, and they carry the challenge text - so the session works with no network in the room.