secure source: reconstruct the PRNG state from the leak, replay it, and recover the flag.
Hash
24 postssignup
signup: reduce the hash constraint to a small search, test candidates, and recover the flag.
alphascii clashing
alphascii clashing: reduce the hash constraint to a small search, test candidates, and recover the flag.
Digital-Safety-Annex
Digital-Safety-Annex: use the curve leak or invalid-curve path to recover the secret and decrypt the flag.
Interception
Interception: model the leak as a small lattice problem, recover the secret, and verify the flag.
Not that random
Not that random: reconstruct the PRNG state from the leak, replay it, and recover the flag.
Permuted
Permuted: exploit the RSA structure, recover the missing secret, and decrypt the flag.
Jenny From The Block
Jenny From The Block: reduce the hash constraint to a small search, test candidates, and recover the flag.
MSS
MSS: exploit the RSA structure, recover the missing secret, and decrypt the flag.
AHS512
AHS512: reconstruct the PRNG state from the leak, replay it, and recover the flag.
Arranged
Arranged: abuse the AES misuse, derive the missing key material, and decrypt the flag.
Bank-er-smith
Bank-er-smith: exploit the RSA structure, recover the missing secret, and decrypt the flag.
Bloom Bloom
Bloom Bloom: abuse the AES misuse, derive the missing key material, and decrypt the flag.
I'm gRoot
I'm gRoot: reduce the hash constraint to a small search, test candidates, and recover the flag.
Android-in-the-Middle
Android-in-the-Middle: abuse the AES misuse, derive the missing key material, and decrypt the flag.
Embryonic Plant
LostKey
ReMeeting the Wheel
Signing Factory
Signing Factory: reconstruct the PRNG state from the leak, replay it, and recover the flag.
Rhome
RsaCtfTool
RsaCtfTool: abuse the AES misuse, derive the missing key material, and decrypt the flag.
Hybrid Unifier
Hybrid Unifier: abuse the AES misuse, derive the missing key material, and decrypt the flag.
SPG
SPG: reconstruct the generator state, derive the AES material, and decrypt the final ciphertext.
Secure Singning
Secure Singning: derive the XOR key stream, invert the transform, and recover the flag.