Files
asepharyana f9ae3d8808 Add bodu (Boneh-Durfee) + crypto_baby reference implementations; 5 verified solves
- examples/bodu: full Boneh-Durfee lattice attack (fpylll LLL + sympy gcd
  extraction), verified on a toy RSA; live instance needs larger m (k>n^0.292)
- examples/crypto_baby: hidden-base knapsack 0/1-digit recovery reference
- examples/README.md: split verified solves (5) from reference implementations
2026-08-17 00:54:47 +07:00
..

Examples — real CTF challenges solved with this toolkit

Every VERIFIED example is reproducible offline (no live server, no sage) and uses lib/crypto_utils.py / lib/net.py where applicable. Solved by distilling patterns from the public p4-team/ctf archive.

Solved (flag recovered)

Challenge Event Category Vuln Flag
ps_and_qs SECCON 2017 Quals Crypto Two RSA keys share a prime (gcd(n1,n2)=p) SECCON{1234567890ABCDEF}
lost_modulus HITCON 2019 Quals Crypto RSA leaks e,d,iqmp,ipmq but not n — recover n hitcon{1t_is_50_easy_t0_find_th3_modulus_back@@!!@!@!@@!}
a2s Pwn2Win 2021 Crypto 2-round reduced AES — differential attack recovers key CTF-BR{bu7_1f_7h0u6h7_c0rrup75_l4n6u463,_l4n6u463_c4n_4l50_c0rrup7_7h0u6h7}
russian_threesome Hack.lu 2020 RE/Misc Inverse-permutation fixed-point on a drum dump (CP1251) Кто хочет много знать, тому мало спать.
mask TokyoWesterns 2020 Misc Host bits of IP/mask list → base64 → flag TWCTF{Are-you-using-a-mask?}

Reference implementations (attack coded, solver recovery pending)

These contain correct, working implementations of the hard attack but the final root/key recovery for the specific live instance needs more tuning (or sage-grade small_roots). Kept as study references, not counted as solved.

Challenge Event Category Implemented attack Blocker
bodu ASIS Finals 2015 Crypto (HARD) Full Boneh-Durfee lattice (LLL via fpylll) + sympy resultant/gcd extraction — verified on a toy RSA Live instance has k=e·d/φ ≈ n^0.325 > 0.292 BD limit; needs larger m / +1 refinement
crypto_baby ASIS Finals 2018 Crypto (HARD) Hidden-base knapsack: base-exp 0/1-digit recovery Live exp/S/key structure resists direct base-2 decode

Run them

cd /home/code/ctfkit

# crypto — self contained
python3 examples/ps_and_qs.py
python3 examples/lost_modulus/solve.py

# a2s — runs the differential attack then extracts the flag
cd examples/a2s && python3 solve.py && cd ../..

# russian_threesome — permutation fixed point
python3 examples/russian_threesome/solve.py

# mask — IP/mask host bits -> base64
python3 examples/mask/solve.py