Skip to content
All modules
CoreModule 8 of 27120 minutes

RSA and the parameters that break it

Work the RSA decision tree - small modulus, close primes, tiny exponent, shared modulus - and learn to read a key for its weakness.

Assumes6. XOR and the cost of reusing a key

By the end you can

  • Recover a private exponent from a factored modulus
  • Choose an attack from the shape of n, e, and the number of ciphertexts
  • Apply Fermat factorization, Wiener's attack, and the common-modulus attack
  • Read the parameters straight out of a PEM or DER key rather than out of the challenge text
  • Explain why textbook RSA without padding enables attacks that padded RSA does not

1. Read

2. Use the tools

In the order they come up while solving. Read what each one does, or go straight to the workspace tab that runs it.

3. Try one now

Generated in your browser and checked in your browser. No account, nothing to download, and a fresh one whenever you want another.

4. Practise on the real thing

Real picoCTF challenges that use these techniques, easiest first. 32 match in total - see the full index.

Common mistakes

The wrong turns this topic reliably produces. Written as the mistake rather than the rule, because the rule is easy to agree with and easy to walk straight past.

  • Running every attack until one succeeds. The parameters name the attack, and a student who cannot say which one before running it has not learned the module.
  • Trying to factor a 2048-bit modulus. If n is that size the weakness is elsewhere - a small e, a shared factor with another key, or a padding oracle.
  • Forgetting that e and d are symmetric in the maths but not in the attacks: a huge e is the signature of a small d, which is Wiener's whole premise.
  • Converting the recovered integer to a decimal string. The plaintext is bytes: render it big-endian, drop the leading zeros, and a result that looked like a failed attack usually turns out to be the flag.
  • Taking an integer root with floating point when e is tiny. The answer is exact only if raising it back reproduces the ciphertext, and without that check an off-by-one root is indistinguishable from m having wrapped n.

Checkpoint

Given three RSA challenges with different weaknesses, name the applicable attack for each before running anything, then verify.

Teaching note

Insist on the prediction step. A student who runs every attack until one succeeds has learned nothing about RSA; a student who says 'e is enormous, so Wiener' has learned the entire module.

Go deeper

The lessons above are written to get you through a challenge. These go after the subject instead. Each one opens our notes on that chapter - what it argues, what to take from it and where it stops - so this is somewhere to read now rather than a book to buy first. Nothing here is affiliate-linked or sold by us.

Every book the curriculum cites has a page in the library.