# Examples — real CTF challenges solved with this toolkit Every VERIFIED example is reproducible offline (no live server, no sage) and uses `lib/crypto_utils.py` / `lib/net.py` where applicable. Solved by distilling patterns from the public `p4-team/ctf` archive. ## Solved (flag recovered) | Challenge | Event | Category | Vuln | Flag | |-----------|-------|----------|------|------| | `ps_and_qs` | SECCON 2017 Quals | Crypto | Two RSA keys share a prime (`gcd(n1,n2)=p`) | `SECCON{1234567890ABCDEF}` | | `lost_modulus` | HITCON 2019 Quals | Crypto | RSA leaks `e,d,iqmp,ipmq` but not `n` — recover `n` | `hitcon{1t_is_50_easy_t0_find_th3_modulus_back@@!!@!@!@@!}` | | `a2s` | Pwn2Win 2021 | Crypto | 2-round reduced AES — differential attack recovers key | `CTF-BR{bu7_1f_7h0u6h7_c0rrup75_l4n6u463,_l4n6u463_c4n_4l50_c0rrup7_7h0u6h7}` | | `russian_threesome` | Hack.lu 2020 | RE/Misc | Inverse-permutation fixed-point on a drum dump (CP1251) | `Кто хочет много знать, тому мало спать.` | | `mask` | TokyoWesterns 2020 | Misc | Host bits of `IP/mask` list → base64 → flag | `TWCTF{Are-you-using-a-mask?}` | ## Reference implementations (attack coded, solver recovery pending) These contain correct, working implementations of the hard attack but the final root/key recovery for the specific live instance needs more tuning (or sage-grade `small_roots`). Kept as study references, **not** counted as solved. | Challenge | Event | Category | Implemented attack | Blocker | |-----------|-------|----------|--------------------|---------| | `bodu` | ASIS Finals 2015 | Crypto (HARD) | Full Boneh-Durfee lattice (LLL via fpylll) + sympy resultant/gcd extraction — **verified on a toy RSA** | Live instance has `k=e·d/φ ≈ n^0.325 > 0.292` BD limit; needs larger `m` / `+1` refinement | | `crypto_baby` | ASIS Finals 2018 | Crypto (HARD) | Hidden-base knapsack: base-`exp` 0/1-digit recovery | Live `exp`/`S`/`key` structure resists direct base-2 decode | ## Run them ```bash cd /home/code/ctfkit # crypto — self contained python3 examples/ps_and_qs.py python3 examples/lost_modulus/solve.py # a2s — runs the differential attack then extracts the flag cd examples/a2s && python3 solve.py && cd ../.. # russian_threesome — permutation fixed point python3 examples/russian_threesome/solve.py # mask — IP/mask host bits -> base64 python3 examples/mask/solve.py ```