2016from public repositories
IRAN Cert Easy 2016
4 challenges with 5 published solutions between them. The writeups for this event were found in public repositories. Each link is pinned to the commit it was read from.
Where these writeups liveCryptography2
Recover a plaintext or a key from something that was supposed to protect it. In practice: identify the scheme, find the parameter the author got wrong, exploit it.
Solve it with:Cipher identifier and automatic decoderVigenere cipher solver with automatic key recoveryRSA decryption and attack runnerWiener’s attack on small RSA private exponentsIn-browser hash cracker with rule transformsLearn: Classical ciphers and frequency analysisLearn: RSA and the parameters that break it
Also written up in: Execut3/CTF, Execut3/CTF
40pt Rsa1
1 official solutionAlso written up in: Execut3/CTF
Steganography1
Find the payload hidden inside a carrier that looks ordinary. Bit planes, appended data, metadata, and audio spectrograms.
Solve it with:LSB steganography extractorPNG chunk analyzerAudio spectrogram and SSTV decoderZero-width character and text steganography decoderLearn: Steganography
Create
1 official solutionAlso written up in: Execut3/CTF
Web1
Reach data or functionality the application meant to keep from you - through its inputs, its tokens, or its trust in the client.
Solve it with:JWT decoder and signature verifierJWT alg=none bypass generatorWeb attack payload catalogJWT secret brute forceLearn: Sessions, tokens and access control
Setup
1 official solutionAlso written up in: Execut3/CTF