Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
xortool — मल्टी-बाइट xor सिफर का विश्लेषण करने के लिए एक टूल | Kitploit
उपकरण/GitHubGitHub/hellman/xortool
स्थैतिक विश्लेषणएन्क्रिप्शन/डिक्रिप्शन उपकरणफोरेंसिकक्रिप्टोग्राफीबाइनरी विश्लेषणलर्निंग और शिक्षा
GitHubhellman/xortool

xortool

मल्टी-बाइट xor सिफर का विश्लेषण करने के लिए एक टूल

रिपॉजिटरी देखें
1.5k1801 साल पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

xortool.py

====================

xor विश्लेषण करने के लिए एक टूल:

  • कुंजी लंबाई का अनुमान लगाएं (समान वर्णों की गिनती के आधार पर)
  • कुंजी का अनुमान लगाएं (सबसे अधिक बार आने वाले वर्ण के ज्ञान के आधार पर)

ध्यान दें: xortool अब केवल Python 3 पर चल रहा है। पुराना Python 2 संस्करण py2 ब्रांच पर उपलब्ध है। pip पैकेज अपडेट कर दिया गया है।

स्थापना

root@kitploit:~
$ pip3 install xortool

इस रिपॉज़िटरी के विकास या निर्माण के लिए, poetry आवश्यक है।

root@kitploit:~
poetry build
pip install dist/xortool*.whl

उपयोग

root@kitploit:~
xortool
  A tool to do some xor analysis:
  - guess the key length (based on count of equal chars)
  - guess the key (base on knowledge of most frequent char)

Usage:
  xortool [-x] [-m MAX-LEN] [-f] [-t CHARSET] [FILE]
  xortool [-x] [-l LEN] [-c CHAR | -b | -o] [-f] [-t CHARSET] [-p PLAIN] [-r PERCENT] [FILE]
  xortool [-x] [-m MAX-LEN| -l LEN] [-c CHAR | -b | -o] [-f] [-t CHARSET] [-p PLAIN] [-r PERCENT] [FILE]
  xortool [-h | --help]
  xortool --version

Options:
  -x --hex                          input is hex-encoded str
  -l LEN, --key-length=LEN          length of the key
  -m MAX-LEN, --max-keylen=MAX-LEN  maximum key length to probe [default: 65]
  -c CHAR, --char=CHAR              most frequent char (one char or hex code)
  -b --brute-chars                  brute force all possible most frequent chars
  -o --brute-printable              same as -b but will only check printable chars
  -f --filter-output                filter outputs based on the charset
  -t CHARSET --text-charset=CHARSET target text character set [default: printable]
  -p PLAIN --known-plaintext=PLAIN  use known plaintext for decoding
  -r PERCENT, --threshold=PERCENT   threshold validity percentage [default: 95]
  -h --help                         show this help

Notes:
  Text character set:
    * Pre-defined sets: printable, base32, base64
    * Custom sets:
      - a: lowercase chars
      - A: uppercase chars
      - 1: digits
      - !: special chars
      - *: printable chars

Examples:
  xortool file.bin
  xortool -l 11 -c 20 file.bin
  xortool -x -c ' ' file.hex
  xortool -b -f -l 23 -t base64 message.enc
  xortool -b -p "xctf{" message.enc
  xortool -r 80 -p "flag{" -c ' ' message.enc

उदाहरण 1

root@kitploit:~
# xor is xortool/xortool-xor
tests $ xor -f /bin/ls -s "secret_key" > binary_xored

tests $ xortool binary_xored
The most probable key lengths:
   2:   5.0%
   5:   8.7%
   8:   4.9%
  10:   15.4%
  12:   4.8%
  15:   8.5%
  18:   4.8%
  20:   15.1%
  25:   8.4%
  30:   14.9%
Key-length can be 5*n
Most possible char is needed to guess the key!

# 00 is the most frequent byte in binaries
tests $ xortool binary_xored -l 10 -c 00
...
1 possible key(s) of length 10:
secret_key

# decrypted ciphertexts are placed in ./xortool_out/Number_<key repr>
# ( have no better idea )
tests $ md5sum xortool_out/0_secret_key /bin/ls
29942e290876703169e1b614d0b4340a  xortool_out/0_secret_key
29942e290876703169e1b614d0b4340a  /bin/ls

सबसे सामान्य उपयोग यह है कि केवल एन्क्रिप्टेड फ़ाइल और सबसे अधिक बार आने वाला वर्ण (आमतौर पर बाइनरी के लिए 00 और टेक्स्ट फ़ाइलों के लिए 20) पास करें - लंबाई स्वचालित रूप से चुनी जाएगी:

root@kitploit:~
tests $ xortool tool_xored -c 20
The most probable key lengths:
   2:   5.6%
   5:   7.8%
   8:   6.0%
  10:   11.7%
  12:   5.6%
  15:   7.6%
  20:   19.8%
  25:   7.8%
  28:   5.7%
  30:   11.4%
Key-length can be 5*n
1 possible key(s) of length 20:
an0ther s3cret \xdd key

यहाँ, कुंजी डिफ़ॉल्ट 32 सीमा से अधिक लंबी है:

root@kitploit:~
tests $ xortool ls_xored -c 00 -m 64
The most probable key lengths:
   3:   3.3%
   6:   3.3%
   9:   3.3%
  11:   7.0%
  22:   6.9%
  24:   3.3%
  27:   3.2%
  33:   18.4%
  44:   6.8%
  55:   6.7%
Key-length can be 3*n
1 possible key(s) of length 33:
really long s3cr3t k3y... PADDING

तो, यदि स्वचालित डिक्रिप्शन विफल हो जाता है, तो आप कैलिब्रेट कर सकते हैं:

  • (-m) लंबी कुंजियों को आज़माने के लिए अधिकतम लंबाई
  • (-l) कुछ दिलचस्प कुंजियों को देखने के लिए चयनित लंबाई
  • (-c) सही प्लेनटेक्स्ट प्राप्त करने के लिए सबसे अधिक बार आने वाला वर्ण

उदाहरण 2

हमें एक संदेश दिया गया है जो Base64 में एन्कोडेड है और एक अज्ञात कुंजी के साथ XOR किया गया है।

root@kitploit:~
# xortool message.enc
The most probable key lengths:
   2:   12.3%
   4:   13.8%
   6:   10.5%
   8:   11.5%
  10:   8.6%
  12:   9.4%
  14:   7.1%
  16:   7.8%
  23:   10.4%
  46:   8.7%
Key-length can be 4*n
Most possible char is needed to guess the key!

अब हम आउटपुट को फ़िल्टर करते हुए कुंजी लंबाई का परीक्षण कर सकते हैं ताकि यह केवल उन प्लेनटेक्स्ट को रखे जिनमें Base64 का वर्ण सेट हो। कुछ लंबाई आज़माने के बाद, हम सही लंबाई पर पहुँचते हैं, जो डिफ़ॉल्ट 95% सीमा से ऊपर मान्य वर्णों के प्रतिशत के साथ केवल 1 प्लेनटेक्स्ट देती है।

root@kitploit:~
$ xortool message.enc -b -f -l 23 -t base64
256 possible key(s) of length 23:
\x01=\x121#"0\x17\x13\t\x7f ,&/\x12s\x114u\x170#
\x00<\x130"#1\x16\x12\x08~!-\'.\x13r\x105t\x161"
\x03?\x103! 2\x15\x11\x0b}".$-\x10q\x136w\x152!
\x02>\x112 !3\x14\x10\n|#/%,\x11p\x127v\x143
\x059\x165\'&4\x13\x17\r{$("+\x16w\x150q\x134\'
...
Found 1 plaintexts with 95.0%+ valid characters
See files filename-key.csv, filename-char_used-perc_valid.csv

आउटपुट को Base64 के वर्ण सेट पर फ़िल्टर करके, हम सीधे केवल एकमात्र समाधान प्राप्त कर लेते हैं।

जानकारी

लेखक: hellman

लाइसेंस: MIT License

टूल डाउनलोड करें