400curves
CTF

400curves

Elliptic Curve Cryptography. Invalid Curve Attack
4ES
CTF

4ES

CrewCTF 2024. AES. Meet-in-the-middle
5x5 Crypto
CTF

5x5 Crypto

Polybius Square
AbraCryptabra
CTF

AbraCryptabra

Truncated LCG. AES. Knapsack. LLL lattice reduction
aes
CTF

aes

ImaginaryCTF 09/08/2022. 50 points. AES. Weak password. Brute force
AESWCM
CTF

AESWCM

Custom encryption using AES and XOR
AESWCM
CTF

AESWCM

HTB UniCTF 2022. Custom encryption using AES and XOR. Bad padding implementation
AHS512
CTF

AHS512

Custom hash function. Bit operations
AHS512
CTF

AHS512

Custom hash function. Bit operations
alphascii clashing
CTF

alphascii clashing

MD5 hash collision with constraints
Ancient Encodings
CTF

Ancient Encodings

Hexadecimal and Base64 encodings
Android-in-the-middle
CTF

Android-in-the-middle

Diffie-Hellman. MITM
Arranged
CTF

Arranged

ECC. Finding curve parameters. Modular arithmetic. ECDLP
Arranged
CTF

Arranged

HTB CA 2024. ECC. Finding curve parameters. Modular arithmetic. ECDLP
baby quick maffs
CTF

baby quick maffs

Related messages attack. Modular arithmetic
Bank-er-smith
CTF

Bank-er-smith

RSA. Known bits. Coppersmith method. LLL lattice reduction
Bank-er-smith
CTF

Bank-er-smith

HTB UniCTF 2022. RSA. Known bits. Coppersmith method. LLL lattice reduction
Base 2 2 the 6
CTF

Base 2 2 the 6

Base64 decoding
BBGun06
CTF

BBGun06

RSA. Forge signature. Regular Expression bypass
BFD56
CTF

BFD56

CBC Bifid cipher
Biased Heritage
CTF

Biased Heritage

Schnorr signature. Hidden Number Problem. LLL lattice reduction
Biased Heritage
CTF

Biased Heritage

HTB CA 2023. Schnorr signature. Hidden Number Problem. LLL lattice reduction
Big RSA
CTF

Big RSA

TeamItaly CTF 2023. RSA. Factorial. Modular arithmetic. Integer division
binary basis
CTF

binary basis

Multiprime RSA. Find private key
Blessed
CTF

Blessed

BLS12-381. BLS signatures. Rogue key attack. Zero-knowledge proof. EC-LCG. LLL lattice reduction
Blind
CTF

Blind

ECSC 2023. First day. ECDSA. Signature verification. XOR
Bloom Bloom
CTF

Bloom Bloom

AES. Shamir Secret Sharing
Box
CTF

Box

ImaginaryCTF 15/09/2022. 50 points. System of linear equations
Brainy's Cipher
CTF

Brainy's Cipher

Brainfuck. RSA with CRT
brevi moduli
CTF

brevi moduli

RSA. Factorization
BruXOR
CTF

BruXOR

XOR brute force
Careless Padding
CTF

Careless Padding

HITCON CTF Quals 2023. Padding Oracle Attack. Custom padding. Guessing
Character Encoding
CTF

Character Encoding

ASCII hexadecimal encoding
Classic, yet complicated!
CTF

Classic, yet complicated!

Vigenère cipher
Close Enough
CTF

Close Enough

SEETF 2022. RSA. Wrong implementation
Clutch
CTF

Clutch

Quantum Cryptography. Frame-based Quantum Key Distribution
Clutch
CTF

Clutch

HTB UniCTF 2024. Quantum Cryptography. Frame-based Quantum Key Distribution
Colliding Heritage
CTF

Colliding Heritage

Schnorr signature. MD5 collision
Colliding Heritage
CTF

Colliding Heritage

HTB CA 2023. Schnorr signature. MD5 collision
Come on feel the nonce
CTF

Come on feel the nonce

CTFZone Quals 2023. ECDSA. Biased nonces. Hidden Number Problem. LLL lattice reduction
Composition
CTF

Composition

Close primes. RSA and ECC. Finding curve parameters. Elliptic curve over composite modulus
Converging Visions
CTF

Converging Visions

ECC. Binary search. Finding curve parameters. Smart’s attack. PRNG
Converging Visions
CTF

Converging Visions

HTB CA 2023. ECC. Binary search. Finding curve parameters. Smart’s attack. PRNG
CryptoConundrum
CTF

CryptoConundrum

AES cipher. Frequency analysis. Depth-first search
cryptoGRAPHy (1, 2, 3)
CTF

cryptoGRAPHy (1, 2, 3)

SekaiCTF 2023. Graph Encryption Scheme

  1. Key leakage. Decryption
  2. Single-Destination Shortest Path. Node degrees
  3. Query recovery. Tree isomorphisms
DHCPPP
CTF

DHCPPP

ChaCha20-Poly1305. Nonce reuse. DNS
Down the Rabinhole
CTF

Down the Rabinhole

Greatest Common Divisor. Modular arithmetic. PKCS7 padding
Easy DSA: Elated once
CTF

Easy DSA: Elated once

ImaginaryCTF 24/01/2023. 100 points. DSA. LCG. Modular system of equations
Easy DSA: Lovely Little Lane
CTF

Easy DSA: Lovely Little Lane

ImaginaryCTF 21/01/2023. 125 points. DSA. Hidden Number Problem. LLL lattice reduction
Easy DSA: The beginning
CTF

Easy DSA: The beginning

ImaginaryCTF 06/01/2023. 50 points. DSA. Modular arithmetic
Ebola Virus
CTF

Ebola Virus

DNA encoding. Substitution cipher. Frequency analysis
El cifrao del cuñao
CTF

El cifrao del cuñao

HackOn CTF 2024. RSA. Binomial theorem. GCD
El Reset de 1745
CTF

El Reset de 1745

HackOn CTF 2024. RSA. LLL lattice reduction. Coppersmith method. ECC. Finding curve parameters. Curve over a composite modulus
ElElGamal
CTF

ElElGamal

Traffic analysis. ElGamal. Modular arithmetic
Elliptic Labyrinth
CTF

Elliptic Labyrinth

ECC. Finding curve parameters. Coppersmith method on a bivariate polynomial
Elliptic Labyrinth
CTF

Elliptic Labyrinth

HTB CA 2023. ECC. Finding curve parameters
Elliptic Labyrinth Revenge
CTF

Elliptic Labyrinth Revenge

HTB CA 2023. ECC. Finding curve parameters. Coppersmith method on a bivariate polynomial
Encryption Master
CTF

Encryption Master

Base64, hexadecimal and binary decoding
Enormous
CTF

Enormous

ImaginaryCTF 05/08/2022. 50 points. RSA. Large modulus and short exponent
eyes
CTF

eyes

corCTF 2023. Matrix equations. Solution to a system of equations
Farfour Post Quantom
CTF

Farfour Post Quantom

Securinets Quals 2023. Matrix operations. Modular arithmetic. Shuffling. Solve system of equations
Fast Carmichael
CTF

Fast Carmichael

Miller-Rabin primality test
Fast Carmichael
CTF

Fast Carmichael

Miller-Rabin primality test
Fibopadcci
CTF

Fibopadcci

Padding Oracle Attack. Custom cipher and padding
Find Marher's Secret
CTF

Find Marher's Secret

RC4. FMS attack
fizzbuzz100
CTF

fizzbuzz100

corCTF 2023. RSA decryption oracle
fizzbuzz101
CTF

fizzbuzz101

corCTF 2023. RSA decryption. LSB oracle
fizzbuzz102
CTF

fizzbuzz102

corCTF 2023. RSA decryption. LSB oracle. LCG
Flippin Bank
CTF

Flippin Bank

AES CBC. Bit Flipping Attack. XOR
Gonna-Lift-Em-All
CTF

Gonna-Lift-Em-All

Modular arithmetic
Gonna-Lift-Them-All
CTF

Gonna-Lift-Them-All

Modular arithmetic
Hash the Filesystem
CTF

Hash the Filesystem

AES CTR. Inverse function of the Python built-in hash function
Hextraordinary
CTF

Hextraordinary

XOR cipher
Hide and seek
CTF

Hide and seek

ECSC 2023. Third day. ECC. Point arithmetic. Discrete logarithm. Pohlig-Hellman
Homomurphy's Law
CTF

Homomurphy's Law

Homomorphic encryption. XOR cipher. AES cipher. Brute force
How The Columns Have Turned
CTF

How The Columns Have Turned

Reverse encryption algorithm
hybrid unifier
CTF

hybrid unifier

E2E encryption. Diffie-Hellman. AES
HyperStream Test #2
CTF

HyperStream Test #2

Bacon Cipher
I know Mag1k
CTF

I know Mag1k

DES. Padding Oracle Attack
I'm gRoot
CTF

I'm gRoot

Merkle Tree. Second preimage attack
Iced Tea
CTF

Iced Tea

TEA. Reverse encryption function
Iced TEA
CTF

Iced TEA

HTB CA 2024. TEA. Reverse encryption function
Infinite Descent
CTF

Infinite Descent

RSA. Close primes. PRNG
Infinite Knapsack
CTF

Infinite Knapsack

Knapsack. Brute force. Modular arithmetic. Shuffling. LLL lattice reduction
Initialization
CTF

Initialization

AES CTR. Stream cipher. XOR
Inside The Matrix
CTF

Inside The Matrix

Matrix operations. Chinese Remainder Theorem
Inside The Matrix
CTF

Inside The Matrix

HTB CA 2023. Matrix operations. Chinese Remainder Theorem
Interception
CTF

Interception

RSA. GCD. Coppersmith method. Euler’s Theorem
Irish Flan
CTF

Irish Flan

ECSC 2023. First day. Quaternions. Matrix equations. Kernel
Jenny From The Block
CTF

Jenny From The Block

Block cipher. Known plaintext attack. Induction. SHA256
Jorge Wants a Token
CTF

Jorge Wants a Token

HackOn CTF 2024. JWT. ECDSA biased nonces. Hidden Number Problem. LLL lattice reduction. Discrete logarithm
Kernel searcher
CTF

Kernel searcher

ECSC 2023. Third day. Isogeny. Finding curve parameters. Discrete logarithm
Living with Elegance
CTF

Living with Elegance

Learning With Errors. Probabilistic oracle
Lost Modulus
CTF

Lost Modulus

RSA. Cube Root Attack
Lucky Number
CTF

Lucky Number

Hack.lu CTF 2023. Mersenne primes. Sum of divisors
LunaCrypt
CTF

LunaCrypt

Binary operations. Simplify and reverse encryption algorithm
Mayday Mayday
CTF

Mayday Mayday

RSA-CRT. Modular arithmetic. Coppersmith method
Mayday Mayday
CTF

Mayday Mayday

HTB UniCTF 2023. RSA-CRT. Modular arithmetic. Coppersmith method
Mind In The Clouds
CTF

Mind In The Clouds

ECDSA. Partially-known nonces. LLL lattice reduction
Mind your Ps and Qs
CTF

Mind your Ps and Qs

picoCTF 2021. 20 points. Factorization. RSA decryption
Mod 26
CTF

Mod 26

picoCTF 2021. 10 points. Substitution cipher. ROT13
Model E1337 - Rolling Code Lock
CTF

Model E1337 - Rolling Code Lock

Advanced web pentesting and cryptanalysis. XXE. Reverse Engineering
Model E1337 v2 - Hardened Rolling Code Lock
CTF

Model E1337 v2 - Hardened Rolling Code Lock

Advanced cryptanalysis. Reverse Engineering
Morse Code
CTF

Morse Code

Decoding a message in Morse code
MSS
CTF

MSS

Mignotte Secret Sharing. Modular arithmetic. Chinese Remainder Theorem
MSS
CTF

MSS

HTB UniCTF 2023. Mignotte Secret Sharing
MSS Revenge
CTF

MSS Revenge

HTB UniCTF 2023. Mignotte Secret Sharing. Modular arithmetic. Chinese Remainder Theorem
Multipage Recyclings
CTF

Multipage Recyclings

AES cipher. XOR properties
Multipage Recyclings
CTF

Multipage Recyclings

HTB CA 2023. AES cipher. XOR properties
Noisy CRC
CTF

Noisy CRC

SekaiCTF 2023. CRC. Chinese Remainder Theorem. Brute force
not crypto
CTF

not crypto

ECSC 2023. Third day. ROT13. Base64 encoding. ASCII bytes
Not that random
CTF

Not that random

HMAC. Hash functions
Nuclear Sale
CTF

Nuclear Sale

PCAP analysis. XOR cipher
One Step Closer
CTF

One Step Closer

Franklin-Reiter related-message attack
Optimus Prime
CTF

Optimus Prime

RSA. Greatest Common Divisor
Oracle Leaks
CTF

Oracle Leaks

RSA. Manger’s attack
Paranormial Commitment Scheme
CTF

Paranormial Commitment Scheme

Plaid CTF 2024. BLS12-381. Elliptic curve pairings. Lagrange interpolation
Partial Tenacity
CTF

Partial Tenacity

RSA. Partially-known private information. Modular arithmetic
Partial Tenacity
CTF

Partial Tenacity

HTB CA 2024. RSA. Partially-known private information. Modular arithmetic
Pederson
CTF

Pederson

HackOn CTF 2025. Zero-knowledge proof. Pedersen commitment
Perfect Synchronization
CTF

Perfect Synchronization

AES cipher. Frequency analysis
Personalized
CTF

Personalized

ImaginaryCTF 07/08/2022. 75 points. RSA. PRNG seed. CRT
plai_n_rsa
CTF

plai_n_rsa

SECCON CTF Quals 2023. RSA. Euler totient function
Play Time
CTF

Play Time

HackOn CTF 2025. Modular arithmetic. Xoshiro256**. LFSR. z3 solver
PolyLCG
CTF

PolyLCG

Securinets Quals 2023. Modular polynomials
pqqp
CTF

pqqp

ImaginaryCTF 07/09/2022. 75 points. RSA. Fermat’s Little Theorem
Prime
CTF

Prime

Balsn CTF 2023. AKS primality test. Carmichael numbers. Euler totient function
Protein Cookies 2
CTF

Protein Cookies 2

Hash length extension attack. Custom hash function
Put a ring on it
CTF

Put a ring on it

ECSC 2023. Third day. Ring signature. Oracle
qcg-k
CTF

qcg-k

corCTF 2023. DSA. Recurrence relation. Nonces
Quadratic Leak
CTF

Quadratic Leak

m0leCon CTF 2025 Teaser. RSA. Modular arithmetic. Polynomial
Quadratic Points
CTF

Quadratic Points

Integer linear relations. LLL lattice reduction. ECDLP. CRT
Rather Secure Attachment
CTF

Rather Secure Attachment

ImaginaryCTF 08/12/2022. 100 points. RSA. Cipolla’s Algorithm
read before you sign
CTF

read before you sign

JWT. ECDSA. Java psychic signatures
Read between the lines
CTF

Read between the lines

CrewCTF 2024. RSA. Integer linear relations. LLL lattice reduction
Relatively Small Arguments
CTF

Relatively Small Arguments

ImaginaryCTF 14/07/2022. 75 points. RSA. Wiener’s attack
Reverse Polarity
CTF

Reverse Polarity

Decoding ASCII binary
Right Decision
CTF

Right Decision

CTFZone Quals 2023. Shamir Secret Sharing. System of equations
RLotto
CTF

RLotto

PRNG. Time-based seed
Rolled my own Crypto
CTF

Rolled my own Crypto

ImaginaryCTF 04/09/2022. 90 points. DSA. Abusing special values
Ron was wrong, Whit is right
CTF

Ron was wrong, Whit is right

ImaginaryCTF 28/11/2022. 75 points. RSA. Greatest Common Divisor. Bad PRNG
Rookie Mistake
CTF

Rookie Mistake

RSA. Modular square root. Smooth primes. Discrete logarithm
Rotating Secret Assembler
CTF

Rotating Secret Assembler

ImaginaryCTF 05/07/2022. 50 points. RSA. Greatest Common Divisor
Roulette
CTF

Roulette

PRNG. Custom Mersenne Twister. System of equations with binary variables
rps-casino
CTF

rps-casino

DiceCTF 2024 Quals. LFSR. Modular arithmetic. z3
RRSSAA
CTF

RRSSAA

ECSC 2023. Third day. Multi-prime RSA. PRNG seed. RSA-CRT decryption
RSA 4.0
CTF

RSA 4.0

SECCON CTF Quals 2023. RSA. Quaternions. GCD
RSA Beginner
CTF

RSA Beginner

RSA. Factorization attack
RSA Noob
CTF

RSA Noob

RSA. Wrong implementation
RSACBC
CTF

RSACBC

HackOn CTF 2025. RSA. XOR. Binomial theorem. GCD
RsaCtfTool
CTF

RsaCtfTool

RSA. Euler’s totient function. AES decryption
RSAgain
CTF

RSAgain

ImaginaryCTF 20/11/2022. 90 points. RSA. Common modulus attack
same
CTF

same

ImaginaryCTF 10/08/2022. 75 points. RSA. Common modulus attack
Scrambled Pizzeria
CTF

Scrambled Pizzeria

TeamItaly CTF 2023. XOR. Permutations and substitutions
Secure Signing
CTF

Secure Signing

Hash function. XOR. Oracle
secure source
CTF

secure source

JWT. ECDSA. Python random state
sekur julius
CTF

sekur julius

Caesar cipher
Share
CTF

Share

HITCON CTF Quals 2023. Shamir Secret Sharing. Lagrange interpolation. Chinese Remainder Theorem. multiprocessing
Signing Factory
CTF

Signing Factory

Modular arithmetic. RSA signature. Malleability
signup
CTF

signup

DSA. Nonce reuse. Modular arithmetic
Small StEps
CTF

Small StEps

HTB CA 2023. RSA. Cube Root Attack
So many 64s
CTF

So many 64s

Multiple Base64 encoding
Space Pirates
CTF

Space Pirates

Shamir Secret Sharing. PRNG seed
SPG
CTF

SPG

Boolean oracle
Spooky RSA
CTF

Spooky RSA

RSA. Greatest Common Divisor
Spooky RSA
CTF

Spooky RSA

RSA. Greatest Common Divisor
Spooky Safebox
CTF

Spooky Safebox

Hack.lu CTF 2023. ECC. ECDSA. Public key recovery. Biased nonces. Hidden Number Problem. LLL lattice reduction
Substitution Cipher
CTF

Substitution Cipher

Guessing substitution cipher
sugar free candies
CTF

sugar free candies

Solution to a non-linear system of equations
Sum-O-Primes
CTF

Sum-O-Primes

picoCTF 2022. 400 points. RSA decryption
Symbols
CTF

Symbols

Quadratic residues. Legendre Symbol
Tapping
CTF

Tapping

picoCTF 2019. 200 points. Morse code
The Three-Eyed Oracle
CTF

The Three-Eyed Oracle

AES ECB oracle
Tough decisions
CTF

Tough decisions

ECSC 2023. First day. Learning With Errors. Modular arithmetic
Tsayaki
CTF

Tsayaki

TEA. Equivalent keys. CBC mode
Tsayaki
CTF

Tsayaki

HTB CA 2024. TEA. Equivalent keys. CBC mode
TurboCipher
CTF

TurboCipher

Recurrence relation. Telescoping series. LCG
Twist and shout
CTF

Twist and shout

ECSC 2023. Third day. ECC. Invalid Curve Attack. Quadratic Twist
two-wrongs
CTF

two-wrongs

corCTF 2024. Quantum Computing. Quantum Error Correction
TwoForOne
CTF

TwoForOne

RSA. Common modulus attack
Ursa Minor
CTF

Ursa Minor

Black Hat MEA CTF 2022. RSA. Binary Search. Smooth primes
Vigenère Cipher
CTF

Vigenère Cipher

Vigenère decryption
Vitrium Stash
CTF

Vitrium Stash

DSA. Modular arithmetic. LLL lattice reduction
Waiting List
CTF

Waiting List

ECDSA. Nonces with known bits. Hidden Number Problem. LLL lattice reduction
Weak RSA
CTF

Weak RSA

RSA. Wiener’s attack
Whole Lotta Candy
CTF

Whole Lotta Candy

AES cipher modes. Stream cipher. Known plaintext attack
Whole Lotta Candy
CTF

Whole Lotta Candy

AES cipher modes. Stream cipher. Known plaintext attack
winter
CTF

winter

DiceCTF 2024 Quals. Winternitz One-Time Signature
WOTS Up
CTF

WOTS Up

ECSC 2023. First day. Winternitz One-Time Signature. Hash functions. Induction
WOTS Up 2
CTF

WOTS Up 2

ECSC 2023. First day. Winternitz One-Time Signature. Hash functions
XORed
CTF

XORed

ImaginaryCTF 02/09/2022. 50 points. XOR cipher
yaonet
CTF

yaonet

DiceCTF 2024 Quals. ECC. Baby-step, giant-step. Meet-in-the-middle
Zombie Rolled
CTF

Zombie Rolled

Fractions. Diophantine equation solution with elliptic curve. RSA signature. LLL lattice reduction. Groebner basis
Zombie Rolled
CTF

Zombie Rolled

HTB UniCTF 2023. Fractions. GCD. RSA signature. Coppersmith method on bivariate polynomial
はやぶさ
CTF

はやぶさ

SekaiCTF 2024. Falcon. Lattice attack on NTRU. BKZ. Key recovery attack
マスタースパーク
CTF

マスタースパーク

SekaiCTF 2024. Isogeny-based cryptography. CSIDH. Discrete logarithm. CRT