← All labs
ExpertCryptographic weakness

A length-extension against a naive MAC

50 points · about 90 minutes · flag format DC{...}
Cryptography

Brief

Cryptography fails far more often from misuse than from broken maths — a predictable random value, a token signed with a guessable key, a hash used where a MAC was needed, an oracle that leaks one bit at a time. The primitive may be sound; the way it is wired is not.

This lab: A length-extension against a naive MAC. Break the guarantee a weak or misused primitive was meant to give.

Work it against your own copy of the target. When you have the flag, submit it below.

Objective

Find where a cryptographic value can be predicted, forged or unwound, and use that weakness to reach protected data. Capture the flag it guards.

Sign in and join the Academy to submit a flag, take hints and track your progress.

Sign in

Walkthrough

Locked until you solve it — or reveal it above, which forfeits the points. 3 hints available before then.