← Breaking Crypto & Race Conditions
ReadingLesson 1 of 4 · 10 min

Understanding cryptographic weakness

What it is

Cryptography fails far more often from misuse than from broken maths — a predictable random value, a token signed with a guessable key, a hash used where a MAC was needed, an oracle that leaks one bit at a time. The primitive may be sound; the way it is wired is not.

How you approach it

  1. Look at any token, signature or random-looking value the app trusts. Is it as unpredictable as it needs to be?
  2. Weak keys, missing signatures and homemade schemes all fail the same way: you can produce a value the server will accept as genuine.
  3. Forge or predict the value the flag sits behind, and present it as if it were legitimately yours.

How it gets fixed

A cryptographic value the server trusted turned out to be predictable or forgeable, so a crafted one was accepted as authentic. That authenticity was all that stood between you and the flag. The fix is a keyed, verified primitive with a properly random, secret key.

Practise it

Every lab in the Cryptographic weakness category drills exactly this. Start at Apprentice and work up.

Sign in to track thisLab: the JWT signed with a guessable secret →