All posts by Ashutosh Ahelleya

18, CSE Student at Amrita University: Amritapuri Campus, Cryptanalyst at bi0s CTF team, Hardcore Reader, Loves contributing to Open Source, Pessimist

Block-size Detection

In the previous blog, “Detecting the mode of block cipher being used” was discussed. In this blog, the second step in the attacking of a block cipher i.e. detecting the block size of the cipher, will be discussed. Link to the implementation script has been given at the end of this post which is written in python.

We need to closely look at the padding implementation in the block cipher in order to get the size of the block used. It is good that we list down the key points: the ones that are given and the ones that are needed to be found out, before jumping to the padding function:


  1. The mode used for encryption.
  2. The standard block cipher encryption used.
  3. The encryption function.
  4. The padding function.

One needs to find out the size of block used, having access to the above things. If  you closely looks at how padding is implemented in any oracle function, you can observe that the number of bytes to be padded is the minimum number of bytes required to be added to the plaintext string, such that the length of the padded string becomes a multiple of the block-size. But a thing to be mentioned here is that the number of bytes to be padded should have a minimum value of 1 and maximum value equal to the block-size.

For example, let the block-size of the cipher be 16 bytes and length of input string be 7 bytes. This gives the number of bytes to be padded equal to 16 – 7 = 8. When the input string is 18 bytes long then the number of bytes to be padded is equal to 16*2 – 18 = 14. When the input string is 16 then the number of bytes to be padded is 16. Generalizing it:

padlen = n - (l % n)

where “padlen” is the number of bytes to be padded, “n” is the block size and “l” is the length of the original unpadded string.

When one encrypts this padded string, the length of the ciphertext remains the same. One catch in the padding function, the length of the ciphertext remains the same when one increases the length of the input string by one each time, until the length of the input string becomes a multiple of the block-size because then an entire block will be added to the plain-text string having length equal to the block-size.

So, to detect the size of the block cipher, one can simply call the encryption function each time, giving a single character as an input and noting the length of the ciphertext for each time. Keep on appending single characters to the input string each time and note down the length of ciphertext each time and checking if the length of the ciphertext generated in the current iteration is equal to the one generated in the previous iteration or not. If not, then one can conclude that an entire block has been added to the original string, and hence the size of the block is equal to the difference between the length of the original string when the length of the ciphertext just changed and the length of its corresponding ciphertext.

Here is the implementation of the exploit:

Cheers! All Hail Cryptography!

AES Mode Detection Oracle

In a series of blogs, attacks on AES- Advanced Encryption Standard, will be discussed. There are a number of steps involved to break a block cipher (AES being one of them):

  1. Recognizing the mode of block cipher being used.
  2. Finding the size of the block being used in the block cipher.
  3. Implementing a suitable attack according the mode of block cipher and the standard encryption used.

In this post, the first step in the attacking of block cipher will be discussed.

According to Shannon’s Theory of Communication, a cipher can be regarded as a perfectly secure cipher if the cipher text reveals no information about the plaintext being encrypted. So, the entire idea behind the attack lies in finding patterns in ciphertext that loosens up the framework on which the encryption standard is based.

There are different modes of encryption being used in a block cipher, but only on ECB (Electronic Code Book) and CBC (Cipher Block Chaining) will be focused as for now.

ECB mode of encryption:

This is the most insecure mode of encryption and one will realize it looking at this representation of ECB mode:


In this mode, same key is used to generate ciphertext block of the corresponding plaintext block. This exposes one vulnerability: since the key and the block cipher encryption algorithm remain the same across the entire process of encryption of plaintext, two plaintext blocks containing the same text, will have the same set of ciphertext blocks. So, in case two of the ciphertext blocks have the same value, the attacker can easily recognize that the plaintext contains a group of characters that are being repeated. This reveals some information about the plaintext and hence, according to Shannon, AES in ECB mode is not a perfectly secure cipher!

For example, let us assume the encryption used is AES and the block size is 16 bytes. Let the plaintext be “abcdefghijklmnopabcdefghijklmnop”. After padding there are three (Three, because the size of the original plaintext is exactly a multiple of block size, thus one more block of padded data has to be added due to reasons of security) blocks in the padded plaintext. What is peculiar about the plaintext is that two of the blocks contain the same data in them, i.e. “abcdefghijklmnop” is the content of two of the blocks! They then generate the same 16-byte ciphertext block!

So, to recognize whether a block cipher uses ECB or CBC mode of encryption, we just need to supply the input in the plaintext such that two plaintext blocks contain the same contents and then observe the corresponding ciphertext. If two of the ciphertext blocks have the same value, the encryption used is ECB otherwise another mode of encryption is used! (CBC in this case as only two modes are being discusses here)

CBC mode of encryption:

This mode of encryption has nullified the vulnerability that is present in the ECB mode of encryption. This mode of encryption is vulnerable to Padding Oracle Attacks and Bit Flipping Attacks which will be discussed in the next few blog posts. The encryption in the CBC mode looks like this:


Although the key used is same for every block, there is an additional step when compared to ECB and that is XORing of the padded plaintext block with a value and then encrypting it using a key. For the first block, the value is generated in a pseudo-random way for the first plaintext block, for the next block onwards, the value is the ciphertext block generated in the previous step.

So, using these essential characterstics peculiar to each mode, we are now able to decide if the cipher is encrypted using a particular mode (ECB or CBC). Following is the link to the python code for detecting this:

See you until next time!

A Tale of Resurrection

“It is difficult to fight against anger, for a man will buy revenge with his soul”

This is a tale of resurrection. Resurrection, not of any human soul or body, but resurrection of ideas. Ideas that still have the potential to petrify every human present on this planet. It has often been observed that terrorist groups often origin in a reaction of death of an infamous idol which the terrorists worship as their master or another terrorist group which was their ally. Even terrorists are humans. They too seek revenge upon the murder of their idol or master. There seems to be only one significant difference between humans and terrorists. Terrorists seek revenge upon the entire human race and humans seek revenge only upon the murderer. The names are different. The motive is same. Revenge. Believe me if I say that humans can go to any extent to seek revenge. It doesn’t give them happiness. It keeps them moving forward. The cycle goes on and surely it never finishes up. I kill you, your loved ones kill me, my loved ones find and kill yours. It never stops and never will. Until we reach the end of humanity.

Take the case of Peshawar School Attacks. The sole reason for the terrorists attacking the school was they wanted vengeance for the murder of their kids by Pakistan Army in the name of tearing away the terrorist settlements. The Army killed their kids; knowingly or unknowingly. The terrorist killed theirs, knowingly. Islam pictures children as the embodiment of Allah, every religion does. It doesn’t matter when it comes to retaliation. Humans are strange.

This is a story of the most powerful terrorist group in this world. This is a story of ISIS. The story dates back to 2006, during the period of De-Ba’athification, when Saddam Hussein was killed by the US Army. According to Iraqis, Syrians and analysts who study the group, almost all of ISIS’ leaders—including the members of its military and security committees and the majority of its emirs and princes—are former Iraqi officers, specifically former members of Saddam Hussein’s Bath government who lost their jobs and pensions in the De-Ba’athification process after that regime was overthrown.

It is interesting to note that some of the officials have admitted that there would have been no ISIS if US Army had not invaded Iraq. So you see, the motive was, to seek revenge! The cycle went on; they conquered places, the army fought, they conquered again, the army retaliated again. It went on. Neither of them cared about the innocent people. Both the sides were dissatisfied with what they achieved each time, like every human.

Let us dig deep into the functioning of ISIS and their ideals:

  1. Working structure: The group works exactly like any government. Abu Bakr Al Baghdadi heads the group and every body of their group is answerable to him. They have a wing which handles the health of their members, another wing handles the finances and so on. Each wing has a head for each province conquered who is answer to Baghdadi.
  2. Propaganda: It has established the Al-Furqan Foundation for Media Production, which produces CDs, DVDs, posters, pamphlets, and web-related propaganda products and official statements. FBI Director James Comey has described ISIS’ “propaganda is unusually slick,” noting that, “They are broadcasting… in something like 23 languages”. The fact that they are broadcasting in 23 languages reflects that they have been quite successful in spreading their ideas.
  3. Finances:According to a 2015 study by the Financial Action Task Force, ISIS’ five primary sources of revenue are as followed :
    • proceeds from the occupation of territory (including control of banks, oil and gas reservoirs, taxation, extortion, and robbery of economic assets)
    • kidnapping for ransom
    • donations from Saudi Arabia and Gulf states, often disguised as meant for “humanitarian charity”
    • material support provided by foreign fighters
    • fund raising through modern communication networks.
      Mind me if I say that there might me secret funding from organisations which we have never thought about would it. Trust is a non existent word in business. Everything comes with an agreement which compromises the social condition of people living in this world.
  4. Idealogy: The members of ISIS follow the extremist version of the Quran and Wahhabism. They are destroying everything in the name of Jihad. It regards Muslims who do not follow the interpretations as infidels. The Black Standard variant of the legendary battle flag of Prophet Muhammad that it has adopted: the flag shows the Seal of Muhammad within a white circle, with the phrase above it, “There is no God but Allah”. Such symbolism has been said to point to ISIS’ belief that it represents the restoration of the caliphate (Khalifa!) of early Islam, with all the political, religious and eschatological ramifications that this would imply. We would discuss about eschatology later in this article. According to some observers, ISIS emerged from the ideology of the Muslim Brotherhood, the first post-Ottoman Islamist group dating back to the late 1920s in Egypt. Again you see, RESURRECTION OF IDEAS!
  5. Eschatology: One difference between ISIS and other Islamist and jihadist movements, including al-Qaeda, is the group’s emphasis on eschatology and apocalypticism – that is, a belief in a final Day of Judgment by God.
  6. Goals: A significant goal of the group has been the foundation of a Sunni Islamic state. Specifically, ISIS has sought to establish itself as a caliphate, an Islamic state led by a group of religious authorities under a supreme leader – the caliph (Khalifa!) – who is believed to be the successor to Prophet Muhammad.

It is high time that we look at both sides of the coin. Pay attention. BOTH SIDES OF THE COIN. The United Nations Commission on Human Rights has stated that ISIS:

“seeks to subjugate civilians under its control and dominate every aspect of their lives through terror, indoctrination, and the provision of services to those who obey”

Now the other side. What the army is doing is terrorism too; it is retaliation. When we look just at one side of the coin, what we become is called blind. Blind in trusting what the government is doing. Now read the quote again, assuming you belong to a family of terrorists of ISIS. So the army:

“seeks to subjugate civilians under its control and dominate every aspect of their lives through terror, indoctrination, and the provision of services to those who obey”

It is all a matter of perspective. For the family of terrorists, they are civilians and for the army men fighting, their families are. Both have the right to live. But peacefully. It could hurt when I say that peace might be a state of mind. Maybe we can never achieve peace in this state of war, of mankind. Maybe the ultimate peace we get is DEATH. Think about it.

What is the definition of terror? Ask yourself this question again and again. If it is about someone killing your loved ones then what the government is doing to the terrorists is terrorism too, in the name of justice. If it is about bomb blasts then think about it again. Two wrongs don’t make a right.

The question which arises now is: Who is going to stop this? I am sure that neither the army is going to put down its arms nor the group is going to. Something will vanish. Most things won’t. Ideas are one among them. Is this what life is all about? Do you all want to leave behind a legacy? Think about it. Do we have to wait till what ISIS believes as eschatology or some apocalypse to decide who among us is wrong. I guess everybody is wrong here. Because nobody is going to step down.

The ideas will never vanish. NEVER. Maybe the army is going to take down all the members of ISIS and the group no longer would exist. But, MARK MY WORDS, there will be a new group emerging from somewhere out there and we will have to fight against it, again. They will fight in the name of Jihad. We will fight in the name of Justice. It will never stop. I will never stop. Neither will you. Nor will they. There will be no peace. Maybe peace is just a state of mind. Maybe we cannot get it. Somebody has to stop. Who will? You, me, they? Who? Ask yourself. Over and Over again.

“Seek and you shall find the repulsive things you hope to find”



Resources: ISIS (Only factual data is collected from this site)




RC3 CTF Writeup – Salad(Crypto 100)

Being a part of bi0s, this was the first time I was able to decode a cipher while the CTF was still going on and the feeling was amazing! I feel extremely lucky to be a part of bi0s with such great seniors who are experienced exploit experts and mentor like Vipin Sir!

Its been more than a month I have joined bi0s, and I am pretty sure that Cryptography will the field I am going to focus upon in Computer Science for the rest of my life, I mean for my Masters and if possible then PhD. My blog from now will primarily focus upon the new ideas that emerge in the field of Cryptography, along with the topics which I learn.

Of Course, I won’t stop writing critical thoughts and ideas of mine!

The question stated:


Category: Cryptography              Points: 100


“The fault, dear Brutus, is not in our stars, but in ourselves.” (I.ii.141) Julius Caesar in William Shakespeare’s Julius Caesar

Cipher Text: 7sj-ighm-742q3w4t

At the first glance, the question looks like one encoded with Caesar(Shift) cipher but it is kinda not so. It involves applying Substitution cipher along with Caesar to get the flag.

So here we go,

Since each flag in the CTF had to start with RC3-2016, it struck me at a point of time if even the encoded message contains RC3-2016, but in encoded form! This forced me to find a relation between the letters and the digits using the first 7 encoded digits and RC3-2016. The pattern that I could make out was this:



Here is the flag: RC3-2016-ROMANGOD

Looking forward to exploring and solving more questions in Cryptography!

Meeting beyond Borders

In the beginning it felt like every other day: repeated hours of technical classes and then coming back to the hostel again. But, it turned out to be completely different. That day, our last period was SaH(Serve an Hour). An hour before SaH, I was tired because the topics taught that day were too complex to be fed into my brain. As I was walking across the floor, it felt my legs were ready for a rebellion to resist my flow but I had the strength to resist the pain. I kept deceiving my mind, it would just be a matter of one hour and then I could finally take some rest(Although we had our FOSS club too, I was fooling I said!). We were told that our main project was to create various presentations on a social topic, visit a school nearby and teach them about it in detail.

As I entered the SaH hall, I saw various foreigners sitting on the seats which looked unusual. Various thoughts were hitting my mind: “What have they come for? Who are they? Where have they come from?” et cetera. As I settled myself on a chair, I saw a long haired, tall, blonde guy who had a professional camera suspended on his neck which amazed me(Conceptual Photography is my hobby and so, it amazed me!). The guy introduced himself, he told his name was Maximilian Teufel and he lived near The Alps, in Germany. Europe has been a paradise for Photography since ages and it has produced quite famous photographers. So it was obvious that I started talking to him. We had a brief talk on how he felt coming to India and the answer was a mixed expression which was exactly I felt about my country.

I asked him questions, he answered them accurately, just the way I want people to answer my questions. We share common interest and common answering method. Like most of the professional photographers, he had a completely different way of looking at things which I could make it out when he was clicking the activities we were doing. Foreigners are usually astonished at the way Indians have the attitude towards the social issues that exist in this world, and so was he.

He had come with his team of Ayudh Europe . All of them came from different places: Netherlands, Austria, Germany, Italy but there was one motive which bound them all; making the society a better place to live and inspiring people to care for the Mother Nature.

I couldn’t cease myself going to him after the class. I was very excited to watch his clicks after arriving here and I was surprised to see that the way he clicked some of his photos was similar to that of mine. I took his contact number, his Facebook id, Instagram id literally everything! I contacted him the same night, sharing him my blogs and how we shared common interests. The most observable characteristic of that guy I remember is his long hair! 🙂 I met the next day itself in the Indian Canteen coincidentally, when I was passing by. This time we talked about Indian Cuisine- Chhole, Puri and what not!

I shared my blog with him that night and we talked like we were a part of the same family!

What urged me to write this blog is how people can have same perspective, even when they are living “Beyond the Borders!”. Day before Yesterday, he posted a photo on his Instagram account and to my surprise it was the same photo I had clicked a month before! It is not a sunset, its a portrait of a person who is meditating on the seashore.

Have a look at this!

This slideshow requires JavaScript.

You maybe from one country and your friend maybe from another but we all humans emerged from the same origin, it is we who created the boundaries in our Mother Earth.

We all are the same, change the perspective and the differences will disappear!

Long Live Humanity!




“The grossest crime is to compromise with injustice and crime. Remember the eternal law: You must give; if you want to get!” – Netaji Subhash Chandra Bose

As the clock struck twelve on the midnight, a new dawn rose, bringing in new hopes for the bright and secure future for our country. For me, Independence Day might not be the day when one reminds the country of what one has achieved till now, but its the day when one reminds the country of what all issues are an obstacle to the country’s development. We hear about the glories everyday from our “lovely” politicians. If we hear it again on the anniversary of our independence, it won’t make any change. Discussing what we really need to work upon to make this country a better place to live in, there is no better day than Independence Day, I suppose. With a country that has so much to be proud of, there are streams we should be ashamed of; when compared to other countries, especially the ones which are tinier than India.

  1. Education– This is the root of all evil. According to the consensus of 2014, India’s overall literacy rate is around 74.04%. Now people might be thinking that we are ahead of our rival country Pakistan, which has a literacy rate of just 56.4%. Now this is what is called “Hallucinating Statistics”. If we look at the number of people illiterate in India and Pakistan, you will see that there are 103 million who are illiterate in Pakistan, while there are around 325 million illiterate people in India, three times the illiterate people in our “beloved” Pakistan. So you see, what we actually see as percentage are not actual statistics! Education can bring a deep impact on the society, as a whole. It is the shortest way to solve the problems existing in our country. Solve this, and surpass others.
  2. Health- “We have everything and we use nothing”. We have the rich Ayurveda, which has the capability of curing the most difficult of diseases. The best of all “Vaidyas”(one of them is Susruta Samhita) had taken their birth in this holy land “India” and we are still lacking in terms of malnutrition, immune system and hygiene. Take the example of Japan. After the country suffered the attacks of Hiroshima and Nagasaki, the country decided to focus so much upon the health sector that now the country has been listed among the top countries in terms of health conditions. Even the life expectancy of Japan makes it to the top, earning it the title of a “Developed Country”.
  3. Society-

    “The best way to find yourself is to lose yourselves in the service of others”-Mahatma Gandhi

    With the country producing such great thinkers and genius people like Swami Vivekananda, the country is suffering from severe problems like dowry system, honour killing. I don’t know what do such people gain after doing such evilish things. Instead they lose all the honour and respect that took so much time for them to earn. The society needs to change its attitude (that could be me or you, anyone!) of having the judgemental attitude towards situations. We have cliched every odd situation as “human behaviour”. One person behaves selfish in some difficult time and people respond it as “natural human behaviour”. A monster, which does all right things in this world, still remains a monster. It would take him no time to gain back the monstrous behaviour because he couldn’t train his mind strong enough to control and not because its natural. So get up, rise and let us make this world a better place to live in!

  4. Economy- Although the GDP(Gross Domestic Product) has increased by 2.9% in past 3 years(which is quite good), there are many scams which has severely affected the economy of our country. Many of them include 2G scam, Commonwealth scam, Coal scam, Fodder Scam(In Bihar). These were the ones which had been revealed in front of the people. Who knows there might be some more scams which are even bigger than these! The politicians have become braver and braver and its our duty to show them the correct path and if necessary push them out of their seats. It is the politicians who must fear the people and not the people! The hike in grain prices is mainly attributed to black marketing of grain storage(They secretly store the grains and don’t sell them until there is a hike in the prices; which indeed earns them superb profits). Its the duty of the government to set up teams that ensure that black marketing does not happen in our country. Also its the duty of people to prevent such things happening in the society(Atleast in our locality!).
  5. Understanding the rights- The people have been given so many privileges to ensure an environment of justice and peace in the country, but not to misuse it; in anyway because then the people lose trust in the Judiciary. There have been so many cases where after years of jail and ill-treatment, the Judiciary comes to know that the person who was sent to jail was not the culprit. That is the paradoxical truth of the Indian Judiciary. With only some amendments, the constitution is similar to that when it was officially assigned! I mean, the world has completely transformed itself and still we follow that constitution. The constitution must be amended in accordance with the current time to avoid such errors and then only the people would be able to live without fear!

So today when we salute the country’s flag, we must visualize all the points again and pledge to contribute to atleast one of them.

Jai Hind! Jai Jawaan, Jai Kisaan!

The sanctity of the law can be maintained only so long as it is the expression of the will of the people!- Bhagat Singh(Translated)

Your suggestions are always welcome!


Statistical Data from:

Guru Purnima 2016 

Mostly celebrated in India and Nepal, this day is the most auspicious day to express our gratitude towards our guru- our teacher. ‘Guru’ stands for ‘the remover of darkness’. It is celebrated on the purnima (full moon day) of the hindu month of ashadha (june- july). This year it is going to be celebrated on the 19th of July. 


According to Hindu mythology, this was the day when Shiva became the adi guru (first guru). This occasion has Buddhist connection too- Buddhists celebrate this day in order to honour Lord Buddha who gave his first religious discourse at Sarnath, Uttar Pradesh. 


In Hindu Mythology, Guru has been put above all even above God. He is the one who has taught us what is right and what isn’t. He is the one who has given us the power to make a decision even in the most difficult times. He taught us wisdom, values which would remain and help us till the last breath. While some provided us with food, He was the one who taught us skills to earn it. 

“गुरु गोबिन्द दोउ खडे काके लागूँ पाँयबलिहारी गुरु आपने गोबिन्द दियो बताय” (Guru and The almighty both are in front of me, whom should I bow first, it is you my Guru, who showed me the path to the Almighty and I should therefore bow to you first) sums it all up! 

What could be better than having a guru by your side, showing you the path to divinity and success? 

Let us all take a pledge to express our gratitude to our gurus, they are really special. 


“Why are most engineers turning out to be unemployed”

There are various factors which are leading to such problems of unemployment and lack of skilled enthusiasts.

1. The most important factor is the parenting system of this generation. There are only few parents who actually encourage undertaking what their children want from their lives. So they usually join engineering as their parents ask them to do so, and since there exists lack of interest for such students, the results are devastating and they turn out to be unskilled and unemployed engineers of our country.

Actually, such people cannot be entitled as engineers. I have read in the dgplug logs that student+degree does not mean you are an engineer.

2. The present education system which is encouraging rat race among the students. They literally put blinds around your eyes like in case of a horse and ask you to follow what they want you to. The system wants you to excel everywhere irrespective of which field you want to master.

And so the quote “Jack of all trades, master of none” has come into existence. This quote is exactly meant for the present generation. We don’t master in what we want, the system wants us to know everything, or else you will be out of the race! And you know children are still children and there is a suitable age to train them as adults.

So you see, every year “hum gadhe produce kar rhe hai, in the form of engineers” – quoted by Mast. Phunsukh Wangdu. And congratulations we could become a part of it if we stop learning, stop working hard for what we want.

3. There comes the next and the final point. The mentality of students. We want everything at the speed of light, money is what we want even faster than the speed of light. This generation can do anything for it. I have learnt while reading dgplug logs that if you write something in capitals, it means either you are stressing upon the words or you are trying to command. So again I quote, this generation can do ANYTHING for it, believe me and we cannot deny that. And so they enter engineering with a mindset that it will earn them enough money and these people usually turnout to be among the unemployed.

Your point of view is always welcome!

©Ashutosh Ahelleya