Solved

Crypt CBC with DES3 (from python)

Posted on 2006-11-06
4
1,774 Views
Last Modified: 2012-06-21
I am trying to convert the folowing python code to perl..
------------------------------------------------------
from Crypto.Cipher import DES3

CALC_3DES = 0x6603
iv = 'testtest'
key = 'testtesttesttest'
nonce = 'testtest'
obj = DES3.new(key, DES3.MODE_CBC, iv)
ciph = obj.encrypt(nonce)
print ciph
------------------------------------------------------
But i get a diffrent output with this:
------------------------------------------------------
use Crypt::CBC;
$iv = 'testtest';
$key = 'testtesttesttest';

$cipher = Crypt::CBC->new(
              -cipher      => DES_EDE3,
                        -key         => $key,
                        -iv          => $iv,
                        -header      => 'none');

$ciphertext = $cipher->encrypt("testtest");
print $ciphertext;
------------------------------------------------------
any ideas?
0
Comment
Question by:mattaustin
  • 2
  • 2
4 Comments
 
LVL 2

Author Comment

by:mattaustin
ID: 17883384
I think it has something do to with CALC_3DES = 0x6603, but i dont know what that is or how to use it...?
0
 
LVL 25

Accepted Solution

by:
clockwatcher earned 290 total points
ID: 17945385
The following seems to work for me:

use MIME::Base64;
use Crypt::CBC;
$iv = "testtest";
$key = "testtesttesttest";
$key = $key.substr($key,0,24-length($key)) if length($key) < 24;  # perl 3DES forces you to use a 112 bit key -- python appears to wrap it

$cipher = Crypt::CBC->new(
                -cipher => DES_EDE3,
                -key    => $key,
                -iv     => $iv,
                -header => 'none',
                -padding => 'null',
                -literal_key => 1
                );

$result = encode_base64($cipher->encrypt("testtest"));
print $result;
print $cipher->decrypt(decode_base64($result)),"\n";

-----
Here's the python side (your script slightly modified to include base64 to get a printable output to compare):

#!/usr/bin/python

from Crypto.Cipher import DES3
import base64

iv = "testtest"
key = "testtesttesttest"
obj = DES3.new(key, DES3.MODE_CBC, iv)

enc = base64.b64encode(obj.encrypt("testtest"))
print enc

dec = DES3.new(key, DES3.MODE_CBC, iv)
print dec.decrypt(base64.b64decode(enc))
0
 
LVL 2

Author Comment

by:mattaustin
ID: 17949466
Thank you, But how exactly did you figure that out?  Did i miss something in a doc or something?
0
 
LVL 25

Expert Comment

by:clockwatcher
ID: 17949582
The python documentation blows to put it mildly.   I just did a bit of experimentation and set some flags based on the Crypt::CBC documentation (http://search.cpan.org/~lds/Crypt-CBC-2.22/CBC.pm) that made sense to set based on the results I was seeing from the python encrypt.  If you have the choice, I'd change your python key to be 24 bytes.   I don't know if it's common practice to reuse the first 8 of the key for the final encrypt (just guessed that it was-- makes sense that it is) but to be on the safe side I'd go with the full key.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many time we need to work with multiple files all together. If its windows system then we can use some GUI based editor to accomplish our task. But what if you are on putty or have only CLI(Command Line Interface) as an option to  edit your files. I…
Email validation in proper way is  very important validation required in any web pages. This code is self explainable except that Regular Expression which I used for pattern matching. I originally published as a thread on my website : http://www…
Explain concepts important to validation of email addresses with regular expressions. Applies to most languages/tools that uses regular expressions. Consider email address RFCs: Look at HTML5 form input element (with type=email) regex pattern: T…
This tutorial demonstrates a quick way of adding group price to multiple Magento products.

929 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now