Cyber Security Labs (Beginner → Advanced)

Lesson 4 of 6

Lab 4 — Cryptography Workshop

Break a Caesar and Vigenère cipher by frequency analysis, then reason about XOR, key exchange and why modern crypto holds.

🟡 Intermediate 120 XP

Learn it

Encryption scrambles a message so only someone with the key can read it.

Old ciphers just shifted letters. Because English uses 'e' far more than any other letter, you can crack them by counting letters.

Modern encryption is different: even with the algorithm published for everyone to inspect, without the key there is nothing to count.

Key terms

Plaintext / ciphertext
The readable message, and its scrambled form after encryption.
Frequency analysis
Cracking a cipher by comparing letter counts with the normal frequencies of the language.
Symmetric key
One shared secret key used for both encryption and decryption, as in AES.
Public key
A freely shared key that encrypts data only the matching private key can decrypt.
Kerckhoffs's principle
Security must rest on the secrecy of the key alone, not the algorithm.

Crack this ciphertext

Ciphertext: 'WKH ILUHZDOO LV GRZQ'. Work like a cryptanalyst, not a guesser.

  1. 11. Look at structure: Word lengths 3, 8, 2, 4 are preserved, so it is a substitution cipher, not a transposition or modern cipher.
  2. 22. Attack the short word: A three-letter word starting a sentence is very often 'THE'. W→T, K→H, H→E is a shift of 3 in each case.
  3. 33. Test the hypothesis: Shift every letter back by 3: WKH → THE, ILUHZDOO → FIREWALL, LV → IS, GRZQ → DOWN.
  4. 44. Confirm: 'THE FIREWALL IS DOWN'. One consistent key of 3 explains every letter — that is what confirms a break.
  5. 55. Level up: Now imagine the key was the word 'KEY' repeating. The same letter no longer maps to the same output, so you must first find the key length before frequency analysis works.
  6. 66. The lesson: Caesar has 25 keys, Vigenère with a 6-letter key has 26^6 ≈ 3 × 10^8 — still nothing. AES-256 has 2^256, more than the atoms in the observable universe.

Brute-forcing every Caesar shift

pythonct = "WKH ILUHZDOO LV GRZQ"

def shift(text, k):
    out = ""
    for ch in text:
        if ch.isalpha():
            out += chr((ord(ch) - 65 - k) % 26 + 65)
        else:
            out += ch
    return out

for k in range(1, 26):
    guess = shift(ct, k)
    if " THE " in " " + guess:
        print(k, guess)

With only 25 keys, brute force plus a crib word like ' THE ' finds the answer instantly.

Sandbox lab

Practise the real technique in a fully simulated environment — no live systems, no real data, nothing leaves your browser.

Cipher-breaking workbench

Break an intercepted message offline. Nothing leaves your browser — the ciphertext is fictional.

Safe simulation
WKH VHFUHW PHHWLQJ LV DW WKUHH SP LQ WKH VHUYHU URRP

Decryption attempt

WKH VHFUHW PHHWLQJ LV DW WKUHH SP LQ WKH VHUYHU URRP

Letter frequency in the ciphertext (English order: ETAOIN…)

H10
W6
U5
K3
V3
P3
L3
Q2

Tip: the most common ciphertext letter probably maps to E or T. A Caesar shift of 3 was Julius Caesar's own choice.

Try it

Complete the XOR cipher so encrypting twice returns the original text.

def xor(data, key):
    return bytes(b ______ key for b in data)

secret = xor(b"attack", 42)
print(xor(secret, 42))  # b'attack'

Challenge

A start-up advertises 'military-grade encryption using our own secret algorithm — nobody knows how it works, so nobody can break it.' Write a technical rebuttal a Year 11 student could follow, then describe what you would actually build instead.

Pick whichever way suits you — every mode earns the same bonus XP.

Write at least 40 more characters to submit.

Mark your own work

Guided walkthrough — 0/7 clues revealed

  1. Clue 1 locked — reveal it only if you get stuck.
  2. Clue 2 locked — reveal it only if you get stuck.
  3. Clue 3 locked — reveal it only if you get stuck.
  4. Clue 4 locked — reveal it only if you get stuck.
  5. Clue 5 locked — reveal it only if you get stuck.
  6. Clue 6 locked — reveal it only if you get stuck.
  7. Clue 7 locked — reveal it only if you get stuck.

Each clue costs 6 XP (never below 30 XP). You'd earn 60 XP right now.

Extension: Explain how TLS uses both asymmetric and symmetric crypto, and why it does not just use RSA for everything.

Quiz time

Question 1 of 4Score 0

A Caesar cipher's keyspace is: