## Implement CBC mode

CBC mode is a block cipher mode that allows us to encrypt irregularly-sized messages, despite the fact that a block cipher natively only transforms individual blocks.

In CBC mode, each ciphertext block is added to the next plaintext block before the next call to the cipher core.

The first plaintext block, which has no associated previous ciphertext block, is added to a "fake 0th ciphertext block" called the initialization vector, or IV.

Implement CBC mode by hand by taking the ECB function you wrote earlier, making it encrypt instead of decrypt (verify this by decrypting whatever you encrypt to test), and using your XOR function from the previous exercise to combine them.

[The file here](https://www.cryptopals.com/static/challenge-data/10.txt) is intelligible (somewhat) when CBC decrypted against "YELLOW SUBMARINE" with an IV of all ASCII 0 (\x00\x00\x00 &c)

### Don't cheat.
Do not use OpenSSL's CBC code to do CBC mode, even to verify your results. What's the point of even doing this stuff if you aren't going to learn from it?


## Test AES primitive
Make sure PyCryptodome API can be used for a hand-rolled CBC mode.

In [1]:
from Crypto.Cipher import AES

In [2]:
key = b"YELLOW SUBMARINE"

In [3]:
cipher = AES.new(key, AES.MODE_ECB)

Single block of plaintext.

In [4]:
test_data = b"some secret text"
len(test_data)

16

In [5]:
ciphertext = cipher.encrypt(test_data)
print(ciphertext.hex(), len(ciphertext))

c4e42ecdc5232819db7d5fb468e56ac9 16


In [6]:
assert test_data == cipher.decrypt(ciphertext)

## DIY CBC mode

In [7]:
from os import urandom
from pwn import xor

In [8]:
iv = urandom(cipher.block_size)
iv.hex()

'c5be4894717580f3749af8ef275286ae'

In [9]:
xor(iv, test_data)

b'\xb6\xd1%\xf1Q\x06\xe5\x90\x06\xff\x8c\xcfS7\xfe\xda'

$C_i = E(K, P_i \oplus C_{i-1})$

In [12]:
c = cipher.encrypt( xor(test_data, iv) )
c.hex()

'91cb5dc29fc41910b557c2ca58d38a93'

$P_i = D(K, C_i) \oplus C_{i-1}$

In [13]:
xor(cipher.decrypt(c), iv)

b'some secret text'