Lesson pack 6 · Core · 90 minutes
XOR and the cost of reusing a key
Break single-byte and repeating-key XOR, then recover both plaintexts from a reused one-time pad by crib dragging.
Print this page for a paper plan - the navigation and links drop out.Student-facing version
Before the session
- Nothing to install. Students need a browser and https://ctfpal.com. Confirm the room can reach it once; after that it works offline.
- Read the lesson yourself first - about 6 minutes.
- Have one worked example ready to paste. The classroom link builder on the instructor page turns it into a URL that opens preloaded.
Objectives
Written as things a student can do afterwards, so they can be assessed rather than asserted.
- Brute-force single-byte XOR and score candidates automatically
- Detect a repeating keysize using normalised Hamming distance
- Recover two plaintexts from a reused pad without ever learning the key
- Explain why key reuse destroys a cipher that is otherwise information-theoretically secure
- Recognise a stream cipher, a keystream generator and a hand-rolled 'custom' scheme as the same construction, and attack the keystream rather than the algorithm
Running order (90 min)
| Time | What happens |
|---|---|
| 0:00-0:09 | Frame the problemWhat the category looks like when you meet it cold, and why the naive approach fails. |
| 0:09-0:27 | Teach the methodThe technique itself, on the board or from the lesson. No tools open yet. |
| 0:27-0:50 | Demonstrate liveSame technique, in the workspace, on your worked example. Narrate every choice. |
| 0:50-1:21 | Practice setStudents work the challenges. Circulate rather than present. |
| 1:21-1:30 | Checkpoint and wrapCollect the artefact, name what comes next. |
Tools used
- XOR cipher decoder and key recovery - XOR text or hex against a key, brute-force single-byte XOR by English scoring, and recover repeating-key XOR by Hamming-distance keysize detection.https://ctfpal.com/?tool=xor-cipher
- XOR crib dragging for many-time pads - Recover both plaintexts when a one-time pad key is reused, by dragging a guessed word along the XOR of two ciphertexts.https://ctfpal.com/?tool=crib-drag
- Hex to text converter - Convert hexadecimal to text and back, tolerating whitespace, commas, and `0x` prefixes. Runs entirely in your browser.https://ctfpal.com/?tool=hex-decoder
- Cipher identifier and automatic decoder - Paste anything and find out what it is. ctfpal runs every decoder and rotation, including multi-pass cascades, and ranks results by English-likeness and flag patterns.https://ctfpal.com/?tool=cipher-identifier
- Recipe builder: chain decodes and transforms - Build a repeatable chain of operations - decode, decompress, XOR, decrypt - see the output after every step, and share the whole thing as a link.https://ctfpal.com/?tool=recipe-builder
Reading
- XOR, crib dragging, and the two-time pad - 6 min. Single-byte XOR, repeating-key XOR, and keystream reuse are three faces of the same weakness. How to recover a key length from Hamming distance, drag a crib across a XOR of two plaintexts, and know when a stream cipher has handed you the answer.
Practice set
Real picoCTF challenges tagged with this module’s techniques, easiest first. Assign the first three in class and the rest as homework.
- Black Cobra Pepper - picoCTF 2026, medium
- C3 - picoCTF 2024, medium
- Custom encryption - picoCTF 2024, medium
- Easy Peasy - picoCTF 2021, medium
- Easy1 - picoCTF 2019, medium
- Guess My Cheese (Part 1) - picoCTF 2025, medium
- Hidden Cipher 1 - picoCTF 2026, medium
- Hidden Cipher 2 - picoCTF 2026, medium
- New Caesar - picoCTF 2021, medium
- AES-ABC - picoCTF 2019, hard
- ChaCha Slide - picoCTF 2025, hard
- Clouds - picoCTF 2021, hard
Checkpoint (gradeable)
Given two ciphertexts under one reused key, recover both plaintexts and describe each crib you used.
Deliberately a produced artefact rather than a quiz question: it is either there or it is not, which makes it fast to mark and hard to bluff. Every tool in ctfpal is deterministic, so two students who did the work correctly hand in the same value.
Where the room gets stuck
The space-XOR-letter trick is the moment this module lands. Show it before the general method: once students see that the XOR of two plaintexts leaks word boundaries for free, crib dragging stops feeling like magic.
- Scoring candidates by 'looks like English' rather than by a character-frequency score, which makes the search unrepeatable and slow.
- Assuming the keysize with the lowest Hamming distance is right. Multiples of the true keysize score almost as well, and the smallest plausible one is usually the answer.
- Trying to recover the key from a two-time pad. You never need it: the XOR of the two ciphertexts is the XOR of the two plaintexts, and cribs go straight into that.
- Filtering single-byte candidates to printable output only. The right key often yields a plaintext carrying newlines, a length prefix or raw bytes, and a printable-only filter discards it before the score is ever read.
- Assuming the repeating key is a word. These challenges use raw bytes as often as text, and a search restricted to ASCII keys quietly excludes the answer while still returning a confident-looking ranking.
If a student wants the subject, not the answer
Chapter-level references, so a student can be pointed at twenty pages rather than at a book. Nothing here is required to complete the module.
- Black Hat Go, Tom Steele, Chris Patten, and Dan Kottmann. Chapter 11, Implementing and Attacking Cryptography. Working stream-cipher code next to the attack on it, which is where key reuse stops being an abstraction.
- Designing Secure Software, Loren Kohnfelder. Chapter 5, Cryptography. States the one-time pad's conditions plainly, so 'reused' reads as a broken precondition rather than bad luck.
If you finish early
- Hand out a challenge from the cross-CTF index in this category - each one has published solutions to compare afterwards.
- Run the same input through Identify and let the class argue with the ranking. Disagreeing with a confidence score is where the technique actually lands.
- Ask a student to break their own example - construct an input that defeats the tool, and explain why.
Take this into a room
Markdown files, built here in your browser. They print, they open in anything, and they carry the challenge text - so the session works with no network in the room.