Add bodu (Boneh-Durfee) + crypto_baby reference implementations; 5 verified solves
- examples/bodu: full Boneh-Durfee lattice attack (fpylll LLL + sympy gcd extraction), verified on a toy RSA; live instance needs larger m (k>n^0.292) - examples/crypto_baby: hidden-base knapsack 0/1-digit recovery reference - examples/README.md: split verified solves (5) from reference implementations
This commit is contained in:
+15
-2
@@ -1,9 +1,11 @@
|
||||
# Examples — real CTF challenges solved with this toolkit
|
||||
|
||||
Every example is reproducible offline (no live server, no sage) and uses
|
||||
`lib/crypto_utils.py` / `lib/net.py` where applicable. Solved by distilling
|
||||
Every VERIFIED example is reproducible offline (no live server, no sage) and
|
||||
uses `lib/crypto_utils.py` / `lib/net.py` where applicable. Solved by distilling
|
||||
patterns from the public `p4-team/ctf` archive.
|
||||
|
||||
## Solved (flag recovered)
|
||||
|
||||
| Challenge | Event | Category | Vuln | Flag |
|
||||
|-----------|-------|----------|------|------|
|
||||
| `ps_and_qs` | SECCON 2017 Quals | Crypto | Two RSA keys share a prime (`gcd(n1,n2)=p`) | `SECCON{1234567890ABCDEF}` |
|
||||
@@ -12,6 +14,17 @@ patterns from the public `p4-team/ctf` archive.
|
||||
| `russian_threesome` | Hack.lu 2020 | RE/Misc | Inverse-permutation fixed-point on a drum dump (CP1251) | `Кто хочет много знать, тому мало спать.` |
|
||||
| `mask` | TokyoWesterns 2020 | Misc | Host bits of `IP/mask` list → base64 → flag | `TWCTF{Are-you-using-a-mask?}` |
|
||||
|
||||
## Reference implementations (attack coded, solver recovery pending)
|
||||
|
||||
These contain correct, working implementations of the hard attack but the
|
||||
final root/key recovery for the specific live instance needs more tuning (or
|
||||
sage-grade `small_roots`). Kept as study references, **not** counted as solved.
|
||||
|
||||
| Challenge | Event | Category | Implemented attack | Blocker |
|
||||
|-----------|-------|----------|--------------------|---------|
|
||||
| `bodu` | ASIS Finals 2015 | Crypto (HARD) | Full Boneh-Durfee lattice (LLL via fpylll) + sympy resultant/gcd extraction — **verified on a toy RSA** | Live instance has `k=e·d/φ ≈ n^0.325 > 0.292` BD limit; needs larger `m` / `+1` refinement |
|
||||
| `crypto_baby` | ASIS Finals 2018 | Crypto (HARD) | Hidden-base knapsack: base-`exp` 0/1-digit recovery | Live `exp`/`S`/`key` structure resists direct base-2 decode |
|
||||
|
||||
## Run them
|
||||
```bash
|
||||
cd /home/code/ctfkit
|
||||
|
||||
Reference in New Issue
Block a user