[{"data":1,"prerenderedAt":572},["ShallowReactive",2],{"navigation_docs":3,"-ciphers-rc4":228,"-ciphers-rc4-surround":569},[4,36],{"title":5,"path":6,"stem":7,"children":8,"icon":35},"Guide","\u002Fguide","1.guide\u002F01.index",[9,11,15,19,23,27,31],{"title":10,"path":6,"stem":7},"Getting Started",{"title":12,"path":13,"stem":14},"Encode and decode","\u002Fguide\u002Ftransform","1.guide\u002F02.transform",{"title":16,"path":17,"stem":18},"Analysis","\u002Fguide\u002Fanalysis","1.guide\u002F03.analysis",{"title":20,"path":21,"stem":22},"CLI","\u002Fguide\u002Fcli","1.guide\u002F04.cli",{"title":24,"path":25,"stem":26},"Agents","\u002Fguide\u002Fagents","1.guide\u002F05.agents",{"title":28,"path":29,"stem":30},"Custom ciphers","\u002Fguide\u002Fcustom","1.guide\u002F06.custom",{"title":32,"path":33,"stem":34},"Playground","\u002Fguide\u002Fplayground","1.guide\u002F07.playground","i-lucide-book-open",{"title":37,"path":38,"stem":39,"children":40,"icon":227},"Ciphers","\u002Fciphers","2.ciphers\u002F00.index",[41,43,47,51,55,59,63,67,71,75,79,83,87,91,95,99,103,107,111,115,119,123,127,131,135,139,143,147,151,155,159,163,167,171,175,179,183,187,191,195,199,203,207,211,215,219,223],{"title":42,"path":38,"stem":39},"Overview",{"title":44,"path":45,"stem":46},"Classical","\u002Fciphers\u002Fclassical","2.ciphers\u002F01.classical",{"title":48,"path":49,"stem":50},"Caesar","\u002Fciphers\u002Fcaesar","2.ciphers\u002F02.caesar",{"title":52,"path":53,"stem":54},"ROT-13","\u002Fciphers\u002Frot13","2.ciphers\u002F03.rot13",{"title":56,"path":57,"stem":58},"ROT-47","\u002Fciphers\u002Frot47","2.ciphers\u002F04.rot47",{"title":60,"path":61,"stem":62},"Atbash","\u002Fciphers\u002Fatbash","2.ciphers\u002F05.atbash",{"title":64,"path":65,"stem":66},"Affine","\u002Fciphers\u002Faffine","2.ciphers\u002F06.affine",{"title":68,"path":69,"stem":70},"Vigenère","\u002Fciphers\u002Fvigenere","2.ciphers\u002F07.vigenere",{"title":72,"path":73,"stem":74},"Beaufort","\u002Fciphers\u002Fbeaufort","2.ciphers\u002F08.beaufort",{"title":76,"path":77,"stem":78},"Autokey","\u002Fciphers\u002Fautokey","2.ciphers\u002F09.autokey",{"title":80,"path":81,"stem":82},"Trithemius","\u002Fciphers\u002Ftrithemius","2.ciphers\u002F10.trithemius",{"title":84,"path":85,"stem":86},"Alberti","\u002Fciphers\u002Falberti","2.ciphers\u002F11.alberti",{"title":88,"path":89,"stem":90},"Playfair","\u002Fciphers\u002Fplayfair","2.ciphers\u002F12.playfair",{"title":92,"path":93,"stem":94},"Polybius square","\u002Fciphers\u002Fpolybius","2.ciphers\u002F13.polybius",{"title":96,"path":97,"stem":98},"Morse code","\u002Fciphers\u002Fmorse","2.ciphers\u002F14.morse",{"title":100,"path":101,"stem":102},"Bacon's cipher","\u002Fciphers\u002Fbacon","2.ciphers\u002F15.bacon",{"title":104,"path":105,"stem":106},"Tap code","\u002Fciphers\u002Ftap-code","2.ciphers\u002F16.tap-code",{"title":108,"path":109,"stem":110},"ADFGVX","\u002Fciphers\u002Fadfgvx","2.ciphers\u002F17.adfgvx",{"title":112,"path":113,"stem":114},"Bifid","\u002Fciphers\u002Fbifid","2.ciphers\u002F18.bifid",{"title":116,"path":117,"stem":118},"Rail fence","\u002Fciphers\u002Frail-fence","2.ciphers\u002F19.rail-fence",{"title":120,"path":121,"stem":122},"Columnar transposition","\u002Fciphers\u002Fcolumnar","2.ciphers\u002F20.columnar",{"title":124,"path":125,"stem":126},"Enigma M3","\u002Fciphers\u002Fenigma","2.ciphers\u002F21.enigma",{"title":128,"path":129,"stem":130},"Block","\u002Fciphers\u002Fblock","2.ciphers\u002F22.block",{"title":132,"path":133,"stem":134},"AES (ECB)","\u002Fciphers\u002Faes","2.ciphers\u002F23.aes",{"title":136,"path":137,"stem":138},"AES (CBC)","\u002Fciphers\u002Faes-cbc","2.ciphers\u002F24.aes-cbc",{"title":140,"path":141,"stem":142},"AES (CFB)","\u002Fciphers\u002Faes-cfb","2.ciphers\u002F25.aes-cfb",{"title":144,"path":145,"stem":146},"AES (OFB)","\u002Fciphers\u002Faes-ofb","2.ciphers\u002F26.aes-ofb",{"title":148,"path":149,"stem":150},"AES (CTR)","\u002Fciphers\u002Faes-ctr","2.ciphers\u002F27.aes-ctr",{"title":152,"path":153,"stem":154},"AES (CCM)","\u002Fciphers\u002Faes-ccm","2.ciphers\u002F28.aes-ccm",{"title":156,"path":157,"stem":158},"AES (OCB)","\u002Fciphers\u002Faes-ocb","2.ciphers\u002F29.aes-ocb",{"title":160,"path":161,"stem":162},"AES (LRW)","\u002Fciphers\u002Faes-lrw","2.ciphers\u002F30.aes-lrw",{"title":164,"path":165,"stem":166},"AES (XTS)","\u002Fciphers\u002Faes-xts","2.ciphers\u002F31.aes-xts",{"title":168,"path":169,"stem":170},"AES (CBC-MAC)","\u002Fciphers\u002Faes-cbc-mac","2.ciphers\u002F32.aes-cbc-mac",{"title":172,"path":173,"stem":174},"AES (passphrase)","\u002Fciphers\u002Faes-passphrase","2.ciphers\u002F33.aes-passphrase",{"title":176,"path":177,"stem":178},"Rijndael (ECB)","\u002Fciphers\u002Frijndael","2.ciphers\u002F34.rijndael",{"title":180,"path":181,"stem":182},"DES (ECB)","\u002Fciphers\u002Fdes","2.ciphers\u002F35.des",{"title":184,"path":185,"stem":186},"DESX (ECB)","\u002Fciphers\u002Fdesx","2.ciphers\u002F36.desx",{"title":188,"path":189,"stem":190},"Triple DES (ECB)","\u002Fciphers\u002Ftriple-des","2.ciphers\u002F37.triple-des",{"title":192,"path":193,"stem":194},"Triple DES (CBC)","\u002Fciphers\u002Ftriple-des-cbc","2.ciphers\u002F38.triple-des-cbc",{"title":196,"path":197,"stem":198},"Blowfish (ECB)","\u002Fciphers\u002Fblowfish","2.ciphers\u002F39.blowfish",{"title":200,"path":201,"stem":202},"IDEA (ECB)","\u002Fciphers\u002Fidea","2.ciphers\u002F40.idea",{"title":204,"path":205,"stem":206},"Lucifer (ECB)","\u002Fciphers\u002Flucifer","2.ciphers\u002F41.lucifer",{"title":208,"path":209,"stem":210},"MARS (ECB)","\u002Fciphers\u002Fmars","2.ciphers\u002F42.mars",{"title":212,"path":213,"stem":214},"Serpent (ECB)","\u002Fciphers\u002Fserpent","2.ciphers\u002F43.serpent",{"title":216,"path":217,"stem":218},"Stream","\u002Fciphers\u002Fstream","2.ciphers\u002F44.stream",{"title":220,"path":221,"stem":222},"Rabbit","\u002Fciphers\u002Frabbit","2.ciphers\u002F45.rabbit",{"title":224,"path":225,"stem":226},"RC4","\u002Fciphers\u002Frc4","2.ciphers\u002F46.rc4","i-lucide-library",{"id":229,"title":224,"body":230,"description":562,"extension":563,"links":564,"meta":565,"navigation":566,"path":225,"seo":567,"stem":226,"__hash__":568},"docs\u002F2.ciphers\u002F46.rc4.md",{"type":231,"value":232,"toc":555},"minimark",[233,237,241,244,249,265,288,291,315,318,322,325,336,430,445,448,452,459,463,466,506,517,521,524,527,530,548,551],[234,235],"cipher-facts",{"name":236},"rc4",[238,239,240],"p",{},"Ron Rivest wrote RC4 for RSA Security in 1987. RC stands for Ron's Code, he says so himself. For seven years it was a trade secret. Then in September 1994 someone posted the source to the Cypherpunks mailing list, anonymously. The name is still a trademark, so free code calls it ARC4 or ARCFOUR, alleged RC4. Same cipher.",[238,242,243],{},"After that it was everywhere. SSL in 1995, WEP on every Wi-Fi card in 1997, TLS in 1999. Why? Because it's tiny. The whole thing fits on a napkin.",[245,246,248],"h2",{"id":247},"how-it-runs","How it runs",[238,250,251,252,256,257,260,261,264],{},"The state is a table ",[253,254,255],"code",{},"S"," of 256 bytes, every value from 0 to 255 exactly once, and two indexes, ",[253,258,259],{},"i"," and ",[253,262,263],{},"j",".",[238,266,267,268,270,271,273,274,277,278,280,281,283,284,287],{},"The key schedule starts with ",[253,269,255],{}," in order. It walks ",[253,272,259],{}," from 0 to 255, adds ",[253,275,276],{},"S[i]"," and the next key byte to ",[253,279,263],{},", and swaps ",[253,282,276],{}," with ",[253,285,286],{},"S[j]",". The key repeats as many times as it takes. After 256 swaps the table is shuffled.",[238,289,290],{},"Then every keystream byte is three moves:",[292,293,294,300,308],"ul",{},[295,296,297,299],"li",{},[253,298,259],{}," goes up by one,",[295,301,302,304,305,307],{},[253,303,263],{}," goes up by ",[253,306,276],{},", and the two entries swap,",[295,309,310,311,314],{},"the byte is ",[253,312,313],{},"S[S[i] + S[j]]",", all mod 256.",[238,316,317],{},"That's it. No rounds, no S-boxes, no blocks. The keystream gets XORed into the text, and decrypting is the same XOR again.",[245,319,321],{"id":320},"keys-and-bytes","Keys and bytes",[238,323,324],{},"The key is hex, 2 to 512 digits, a whole number of bytes. Case doesn't matter and spaces are ignored. There's no IV. Text goes in as UTF-8, ciphertext comes out as lowercase hex.",[238,326,327,328,331,332,335],{},"Most RC4 keys out there are passwords, not hex. So a password goes in as its bytes. ",[253,329,330],{},"Secret"," is ",[253,333,334],{},"536563726574",":",[337,338,343],"pre",{"className":339,"code":340,"language":341,"meta":342,"style":342},"language-ts shiki shiki-themes ciphers ciphers ciphers","const rc4 = create(\"rc4\");\nconst key = \"536563726574\";\nrc4.encode(\"Attack at dawn\", { key }).text; \u002F\u002F \"45a01f645fc35b383552544b9bf5\"\nrc4.decode(\"45a01f645fc35b383552544b9bf5\", { key }).text; \u002F\u002F \"Attack at dawn\"\n","ts","",[253,344,345,375,391,412],{"__ignoreMap":342},[346,347,350,354,358,361,365,368,372],"span",{"class":348,"line":349},"line",1,[346,351,353],{"class":352},"skH_V","const",[346,355,357],{"class":356},"s38Sx"," rc4 ",[346,359,360],{"class":352},"=",[346,362,364],{"class":363},"sK71F"," create",[346,366,367],{"class":356},"(",[346,369,371],{"class":370},"shU9J","\"rc4\"",[346,373,374],{"class":356},");\n",[346,376,378,380,383,385,388],{"class":348,"line":377},2,[346,379,353],{"class":352},[346,381,382],{"class":356}," key ",[346,384,360],{"class":352},[346,386,387],{"class":370}," \"536563726574\"",[346,389,390],{"class":356},";\n",[346,392,394,397,400,402,405,408],{"class":348,"line":393},3,[346,395,396],{"class":356},"rc4.",[346,398,399],{"class":363},"encode",[346,401,367],{"class":356},[346,403,404],{"class":370},"\"Attack at dawn\"",[346,406,407],{"class":356},", { key }).text; ",[346,409,411],{"class":410},"scIB-","\u002F\u002F \"45a01f645fc35b383552544b9bf5\"\n",[346,413,415,417,420,422,425,427],{"class":348,"line":414},4,[346,416,396],{"class":356},[346,418,419],{"class":363},"decode",[346,421,367],{"class":356},[346,423,424],{"class":370},"\"45a01f645fc35b383552544b9bf5\"",[346,426,407],{"class":356},[346,428,429],{"class":410},"\u002F\u002F \"Attack at dawn\"\n",[238,431,432,433,436,437,440,441,444],{},"That's the third example from Wikipedia's RC4 page. Want the raw keystream? Encrypt zero bytes. Under ",[253,434,435],{},"Key"," (",[253,438,439],{},"4b6579",") the first ten come out as ",[253,442,443],{},"eb9f7781b734ca72a719",", same as the page says.",[238,446,447],{},"Nothing is dropped from the start of the keystream. Some protocols throw the first bytes away, 768 or more, and call it RC4-drop. This is plain RC4, the one RFC 6229 and OpenSSL run.",[245,449,451],{"id":450},"checked-against","Checked against",[238,453,454,455,458],{},"RFC 6229 publishes keystream for 14 keys, from 40 to 256 bits, at offsets up to 4096. The tests take three of those keys at offsets 0, 1008 and 4096. Every one of the 252 rows matched in a local run too. Then the three Wikipedia examples both ways, and UTF-8 text against ",[253,456,457],{},"openssl enc -rc4"," with the legacy provider on.",[245,460,462],{"id":461},"no-iv-so-dont-reuse-the-key","No IV, so don't reuse the key",[238,464,465],{},"Same key, same keystream. Always. XOR two ciphertexts and the key drops out:",[337,467,469],{"className":339,"code":468,"language":341,"meta":342,"style":342},"rc4.encode(\"Attack at dawn\", { key }).text; \u002F\u002F \"45a01f645fc35b383552544b9bf5\"\nrc4.encode(\"Attack at dusk\", { key }).text; \u002F\u002F \"45a01f645fc35b383552545f9ff0\"\n\u002F\u002F XOR: \"0000000000000000000000140405\"\n",[253,470,471,485,501],{"__ignoreMap":342},[346,472,473,475,477,479,481,483],{"class":348,"line":349},[346,474,396],{"class":356},[346,476,399],{"class":363},[346,478,367],{"class":356},[346,480,404],{"class":370},[346,482,407],{"class":356},[346,484,411],{"class":410},[346,486,487,489,491,493,496,498],{"class":348,"line":377},[346,488,396],{"class":356},[346,490,399],{"class":363},[346,492,367],{"class":356},[346,494,495],{"class":370},"\"Attack at dusk\"",[346,497,407],{"class":356},[346,499,500],{"class":410},"\u002F\u002F \"45a01f645fc35b383552545f9ff0\"\n",[346,502,503],{"class":348,"line":393},[346,504,505],{"class":410},"\u002F\u002F XOR: \"0000000000000000000000140405\"\n",[238,507,508,509,512,513,516],{},"That's ",[253,510,511],{},"dawn"," XOR ",[253,514,515],{},"dusk",". Rabbit at least has an IV for this. RC4 doesn't, so a protocol has to mix its own nonce into the key. WEP did exactly that, glued a 24-bit IV onto the key. Bad idea.",[245,518,520],{"id":519},"how-broken-is-it","How broken is it",[238,522,523],{},"Very. Fluhrer, Mantin and Shamir showed in 2001 that the first keystream bytes leak the key when keys are related. That's how WEP fell. Klein found more leaks in 2005, and aircrack-ptw turned them into a 104-bit WEP key in under a minute.",[238,525,526],{},"The output isn't even random. Mantin and Shamir found the second byte is zero with probability 1\u002F128, not 1\u002F256. You can see it yourself. Take 200,000 random 16-byte keys and look at byte two. It's zero about twice as often as byte one.",[238,528,529],{},"RFC 7465 banned RC4 from every version of TLS in February 2015. So why is it here? Because CTFs and old puzzles still use it, and somebody has to decrypt them.",[238,531,532,533,536,537,540,541,543,544,547],{},"A key that isn't 2 to 512 hex digits, or isn't whole bytes, is an ",[253,534,535],{},"InvalidOptionError",". A missing key is a ",[253,538,539],{},"MissingOptionError",". On ",[253,542,419],{},", an odd number of hex digits is a ",[253,545,546],{},"CipherError",". No padding means only the UTF-8 check catches a wrong key, and a short message can still slip through as valid garbage.",[238,549,550],{},"Plain TypeScript, no integrity check, not constant time. Puzzles and learning, not secrets.",[552,553,554],"style",{},"html pre.shiki code .skH_V, html code.shiki .skH_V{--shiki-light:var(--shiki-token-keyword);--shiki-default:var(--shiki-token-keyword);--shiki-dark:var(--shiki-token-keyword)}html pre.shiki code .s38Sx, html code.shiki .s38Sx{--shiki-light:var(--ui-text-highlighted);--shiki-default:var(--ui-text-highlighted);--shiki-dark:var(--ui-text-highlighted)}html pre.shiki code .sK71F, html code.shiki .sK71F{--shiki-light:var(--shiki-token-function);--shiki-default:var(--shiki-token-function);--shiki-dark:var(--shiki-token-function)}html pre.shiki code .shU9J, html code.shiki .shU9J{--shiki-light:var(--shiki-token-string);--shiki-default:var(--shiki-token-string);--shiki-dark:var(--shiki-token-string)}html pre.shiki code .scIB-, html code.shiki .scIB-{--shiki-light:var(--shiki-token-comment);--shiki-default:var(--shiki-token-comment);--shiki-dark:var(--shiki-token-comment)}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":342,"searchDepth":377,"depth":377,"links":556},[557,558,559,560,561],{"id":247,"depth":377,"text":248},{"id":320,"depth":377,"text":321},{"id":450,"depth":377,"text":451},{"id":461,"depth":377,"text":462},{"id":519,"depth":377,"text":520},"Rivest's stream cipher from 1987. A key of 1 to 256 bytes shuffles a table of 256 byte values into keystream. UTF-8 text in and hex out with no padding.","md",null,{},true,{"title":224,"description":562},"d5SJURrRTgOKEwh68mXDLc-vTOJNPjLHZoTxFYTytlo",[570,564],{"title":220,"path":221,"stem":222,"description":571,"children":-1},"The eSTREAM stream cipher from RFC 4503. A 128-bit key and an optional 64-bit IV give 16 bytes of keystream per step. UTF-8 text in and hex out with no padding.",1790843585593]