Lab Objective

Google Cybersecurity Certificate activity: “Decrypt an encrypted message.” Use Linux Bash commands to find a hidden Caesar-cipher file, decrypt it to reveal the real decryption command, then use that command with OpenSSL to decrypt an AES-256-CBC encrypted file and recover the hidden message.


Lab Environment

  • Course: Google Cybersecurity Certificate
  • Starting directory: /home/analyst (user analyst, already logged in)
  • Files present: Q1.encrypted, README.txt, and a caesar subdirectory

Scenario

All files in the home directory have been encrypted. The task is to break a Caesar cipher hidden in the caesar subdirectory to reveal the exact command needed, then use that command to decrypt Q1.encrypted and recover the hidden message.


Step 1 - Read the Instructions

ls
cat README.txt

ls shows Q1.encrypted, README.txt, and the caesar subdirectory. README.txt reads:

Hello,
All of your data has been encrypted. To recover your data, you will need to solve a cipher. To get started look for a hidden file in the caesar subdirectory.

Step 2 - Find and Decrypt the Hidden Caesar Cipher File

cd caesar
ls -al

Shows a hidden file, .leftShift3 — hidden files in Linux start with a period, and don’t appear under a plain ls.

cat .leftShift3

Output was scrambled ciphertext. The filename itself is the hint: leftShift3 means each letter was shifted three positions to the left in the alphabet (a Caesar cipher), so decrypting means shifting back to the right by three:

cat .leftShift3 | tr "d-za-cD-ZA-C" "a-zA-Z"

The tr command maps one character set to another. "d-za-cD-ZA-C" represents the shifted alphabet; "a-zA-Z" is the real one. Feeding the shifted text through this translation recovers the original message:

In order to recover your files you will need to enter the following command:

openssl aes-256-cbc -pbkdf2 -a -d -in Q1.encrypted -out Q1.recovered -k ettubrute

Step 3 - Decrypt the AES-256 File

Back in the home directory:

cd ~
openssl aes-256-cbc -pbkdf2 -a -d -in Q1.encrypted -out Q1.recovered -k ettubrute
ls
cat Q1.recovered

Output:

If you are able to read this, then you have successfully decrypted the classic cipher text. You recovered the encryption key that was used to encrypt this file. Great work!

Note from my actual run: my first attempt at the openssl command failed with Can't open "Q1.encrypted" for reading, No such file or directory — I had run it from inside the caesar subdirectory instead of returning to the home directory first (cd ~). Re-running it from /home/analyst, where Q1.encrypted actually lives, succeeded immediately. Worth recording honestly: the fix wasn’t a syntax problem, it was a working-directory problem, and checking pwd before running a file-path-dependent command would have caught it before the error did.


Command Breakdown

Flag Meaning
aes-256-cbc The cipher: AES with a 256-bit key, CBC mode
-pbkdf2 Adds key-derivation hardening on top of the raw password
-a Input/output is base64-encoded
-d Decrypt (as opposed to encrypt)
-in / -out Input and output file paths
-k The password/key (ettubrute in this lab)

Security Takeaways

  1. Hidden files are a real, if weak, obscurity layer — never a security boundary. .leftShift3 was trivial to find with ls -a; obscurity bought nothing against anyone who knew to look.
  2. A Caesar cipher is a teaching tool, not real security. Fixed-shift substitution with only 25 possible shifts is broken by brute force in seconds — the lab uses it specifically because it’s easy to reason about by hand.
  3. AES-256-CBC with PBKDF2 key derivation is the real-world contrast. Unlike the Caesar cipher, this is a cipher actually considered safe against brute force at current computing power.
  4. The working directory matters as much as the command syntax. My own decrypt command failed not because the OpenSSL syntax was wrong, but because I ran it from the wrong directory — a reminder that file-path errors and cryptography errors can look identical in the terminal until you actually read the message.
  5. A password given in plaintext (-k ettubrute) is a lab convenience, not a real-world pattern. In practice, passing a key on the command line risks it landing in shell history or process listings — a key management system or an interactive prompt is the safer real-world equivalent.

Where This Applies Beyond the Lab

The gap between the Caesar cipher (trivially breakable) and AES-256-CBC (currently unbroken) in the same lab is a deliberate, concrete illustration of why key length and algorithm choice matter — the Caesar cipher’s “key” is really just one of 25 possible shifts, while AES-256 has 2^256 possible keys. Recognizing which category a given encryption scheme falls into — a toy cipher versus an approved, vetted standard — is exactly the judgment call from the Kerckhoff’s-principle material: never trust a cryptographic scheme because it “looks complicated,” trust it because it’s been proven unbreakable under public scrutiny.