> For the complete documentation index, see [llms.txt](https://cajac.gitbook.io/ctf-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cajac.gitbook.io/ctf-notes/encoding-and-decoding/url.md).

# URL

URL encoding, officially known as percent-encoding, is a method to [encode](https://en.wikipedia.org/wiki/Binary-to-text_encoding) arbitrary data in a [uniform resource identifier](https://en.wikipedia.org/wiki/Uniform_resource_identifier) (URI) using only the [US-ASCII](https://en.wikipedia.org/wiki/ASCII) characters legal within a URI. Although it is known as *URL encoding*, it is also used more generally within the main [Uniform Resource Identifier](https://en.wikipedia.org/wiki/Uniform_Resource_Identifier) (URI) set, which includes both [Uniform Resource Locator](https://en.wikipedia.org/wiki/Uniform_Resource_Locator) (URL) and [Uniform Resource Name](https://en.wikipedia.org/wiki/Uniform_Resource_Name) (URN). Consequently, it is also used in the preparation of data of the `application/x-www-form-urlencoded` [media type](https://en.wikipedia.org/wiki/Media_type), as is often used in the submission of HTML [form](https://en.wikipedia.org/wiki/Form_\(web\)) data in [HTTP](https://en.wikipedia.org/wiki/HTTP) requests.

## URL-decoding

### URL-decode in Bash

```bash
#!/bin/bash

URL="%59%69%70%70%65%68%21%20%59%6F%75%72%20%55%52%4C%20%69%73%20%63%68%61%6C%6C%65%6E%67%65%2F%74%72%61%69%6E%69%6E%67%2F%65%6E%63%6F%64%69%6E%67%73%2F%75%72%6C%2F%73%61%77%5F%6C%6F%74%69%6F%6E%2E%70%68%70%3F%70%3D%61%62%67%6D%61%66%65%62%68%6D%62%64%26%63%69%64%3D%35%32%23%70%61%73%73%77%6F%72%64%3D%66%69%62%72%65%5F%6F%70%74%69%63%73%20%56%65%72%79%20%77%65%6C%6C%20%64%6F%6E%65%21"
echo $URL | tr -d '%' | xxd -r -p
```

### URL-decode with Binary Refinery

You can URL-decode with [url](https://binref.github.io/#refinery.url) from Binary Refinery

```bash
┌──(kali㉿kali)-[~]
└─$ source ~/Python_venvs/Binary_Refinery/bin/activate

┌──(Binary_Refinery)─(kali㉿kali)-[~]
└─$ emit '%56%65%72%79%20%77%65%6C%6C%20%64%6F%6E%65%21' | url 
Very well done!
```

### URL-decode with hURL

You can decode with the Perl-script hURL

```bash
┌──(kali㉿kali)-[~/OffSec_Courses/PEN-200]
└─$ hURL -u '%4f%53%7b%65%64%39%63%31%35%31%38%66%31%62%30%65%62%32%39%34%66%30%38%34%61%34%30%36%38%32%39%62%35%39%32%7d'

Original    :: %4f%53%7b%65%64%39%63%31%35%31%38%66%31%62%30%65%62%32%39%34%66%30%38%34%61%34%30%36%38%32%39%62%35%39%32%7d         
URL DEcoded :: OS{ed9c1518f1b0eb294f084a406829b592}
```

### URL-decode in Python

You can URL-decode in Python with [unquote](https://docs.python.org/3/library/urllib.parse.html#urllib.parse.unquote) from [urllib.parse](https://docs.python.org/3/library/urllib.parse.html#module-urllib.parse)

```python
#!/usr/bin/python

from urllib.parse import unquote

enc = '%59%69%70%70%65%68%21%20%59%6F%75%72%20%55%52%4C%20%69%73%20%63%68%61%6C%6C%65%6E%67%65%2F%74%72%61%69%6E%69%6E%67%2F%65%6E%63%6F%64%69%6E%67%73%2F%75%72%6C%2F%73%61%77%5F%6C%6F%74%69%6F%6E%2E%70%68%70%3F%70%3D%61%62%67%6D%61%66%65%62%68%6D%62%64%26%63%69%64%3D%35%32%23%70%61%73%73%77%6F%72%64%3D%66%69%62%72%65%5F%6F%70%74%69%63%73%20%56%65%72%79%20%77%65%6C%6C%20%64%6F%6E%65%21'
print(unquote(enc))
```

## URL-encoding

### URL-encoding in Python

You can URL-encode in Python with different [URL quoting functions](https://docs.python.org/3/library/urllib.parse.html#url-quoting) from [urllib.parse](https://docs.python.org/3/library/urllib.parse.html#module-urllib.parse)

```python
#!/usr/bin/python

from urllib.parse import quote

string = 'This is a test string!'
print(quoute(string))
```

## Resources

Binary Refinery - Documentation: <https://binref.github.io/>

Binary Refinery - GitHub: <https://github.com/binref/refinery/>

HTML URL Encoding Reference - W3Schools: <https://www.w3schools.com/tags/ref_urlencode.asp>

hURL - GitHub: <https://github.com/fnord0/hURL>

hURL - Kali Tools: <https://www.kali.org/tools/hurl/>

Percent-encoding - Wikipedia: <https://en.wikipedia.org/wiki/Percent-encoding>

urllib package - Python: <https://docs.python.org/3/library/urllib.html>
