CyBRICS Quals 2019 / Published

Honey, Help!

Mapping garbled terminal symbols back to letters with a chosen-plaintext attack to recover the flag.

misc

2 min read

Challenge brief

HONEY HELP!!! I was working in my Kali MATE, pressed something, AND EVERYTHING DISAPPEARED! I even copied the text from terminal

Identifying the garbled terminal output

Garbled terminal output that hides the commands and the flag

In this challenge, we are asked to decipher the flag from the image above. It seems that running echo $'\e(0' majorly screws up terminal output, which does a pretty good job at obscuring the subsequent commands. If we look closely and do some visual pattern matching, it’s evident that the last command typed by the user is cat flag, which means the second-last line of output would be the flag.

Printing \e(0 sends ESC ( 0, which switches the terminal’s G0 character set to DEC Special Graphics. The bytes stay the same, but lowercase letters and a few symbols such as braces are drawn as graphics glyphs: line segments, ▒, ≤, π, £ and so on. Digits, capitals, $, ? and (in this terminal) _ are left alone.

What ESC ( 0 changes about the characters a terminal drawsESC ( 0 selects DEC Special Graphics for the G0 character set and ESC ( B restores ASCII, while the bytes being printed stay the same. Code points 0x20 to 0x5E (space, digits, capitals, most punctuation) draw as themselves, and 0x60 to 0x7E draw as symbols; for example, a becomes a shaded block, q a horizontal line, x a vertical line, y a less-than-or-equal sign, { pi and } a pound sign. 0x5F, the underscore, varies by terminal and survived in this capture.G0: ASCIIG0: DEC graphicsESC ( 0ESC ( Btyped as echo $'\e(0'unchanged: space, 0–9, A–Z, most punctuationredrawn0x200x41 A0x61 a0x7E0x5F _ variesL → L4 → 4$ → $? → ?a →q →x →y → ≤{ →} → £same bytes, different glyphs
Figure 1. ESC ( 0 swaps the terminal's glyph table, not the bytes. Only lowercase letters and a few symbols such as braces are redrawn, so one lookup table recovers the flag.

Mapping symbols to recover the flag

While attempting to decipher the flag, I realized that it would be more efficient if I had a complete mapping of all the weird symbols to the actual letters. After some thought, it occurred to me that replicating this on my system would allow me to execute a Chosen-Plaintext Attack. So I did exactly that, and proceeded to key in a to z and {}.

The author's terminal after switching character sets: the prompt is garbled, and typing a to z and braces shows each one's replacement glyph

Great! Now I have a mapping of all the characters to symbols. All that’s left is to decode the flag.

Python
#! /usr/bin/python3

ciphertext = '▒␉␌␍␊°±␤␋┘┐┌└┼⎺⎻─⎼⎽├┤┴┬│≤≥π£'
plaintext = 'abcdefghijklmnopqrstuvwxyz{}'
mapping = {i:j for i, j in zip(ciphertext, plaintext)}

with open('honey_help.txt') as f:
    data = f.read().split()[-2]

print(''.join([mapping.get(i, i) for i in data]))

Running the script above gets us the flag.

Text
vagrant@ubuntu-cosmic:/vagrant/honey-help$ python3 xpl.py

cybrics{h0ly_cr4p_1s_this_al13ni$h_0r_w4t?}

Result

Flag: cybrics{h0ly_cr4p_1s_this_al13ni$h_0r_w4t?}