thoughtasylumTOOLBOX Preview

Tools › Ciphers

XOR Cipher

XOR text, hex or Base64 with a repeating key, and break single-byte and repeating-key XOR by trying keys and scoring the results.

About this tool What it's for, how to use it and an example

What it's for

Combine data with a key using XOR (exclusive or), the operation inside most modern ciphers, and break simple XOR encryption when the key is unknown. Repeating-key XOR turns up in capture-the-flag challenges, malware and badly written software.

For example, when a CTF challenge gives you a hex string “encrypted with a single byte”, choose Find a single-byte key and read the answer.

How to use it

Choose what the input is (text, hex or Base64), what the key is (text or hex) and how to show the result. The result changes as you type, with the key repeated as often as needed. XOR is its own inverse: XOR the result with the same key to get the input back. These choices are remembered.

Find a single-byte key tries all 256 keys; Find a repeating key estimates the key length from how alike blocks of the input are, then finds each key byte. Both list the most text-like results, best first; choose a key’s name to use it.

Example

With Input is set to Hex, paste:

674f4f5e0a474f0a4b5e0a5e424f0a4858434e4d4f0a4b5e0a44454544060a4b444e0a485843444d0a5e424f0a474b5a04

and choose Find a single-byte key. The top result is Key 2a (“*”): Meet me at the bridge at noon, and bring the map.

Good to know

Breaking assumes the plain text is English or similar text. Repeating keys need several times the key’s length of input: a 7-byte key on 60 bytes can come out with a byte or two wrong, which shows as the odd wrong letter. Key lengths up to 40 bytes are tried. In text view, bytes that aren’t printable ASCII show as ·. A key that is truly random, used once and as long as the message, is a one-time pad and can’t be broken.

Private: this tool runs in your browser. Nothing you type, paste or choose leaves this page.

Saved you a few minutes? Say thanks with a coffee.

Something wrong with this tool, or missing from it? Report a bug or suggest a feature.

↑ ↓ move↵ openesc close