Cryptography
Weak randomness, broken signing and the padding oracle that reads your ciphertext back.
8
labsPractitionerCryptographic weakness
A password-reset token you can predict
Break the guarantee a weak or misused primitive was meant to give.
25 pts · 45 minStart →
PractitionerCryptographic weakness
An ECB-mode image that leaks its shape
Break the guarantee a weak or misused primitive was meant to give.
25 pts · 45 minStart →
ExpertCryptographic weakness
A length-extension against a naive MAC
Break the guarantee a weak or misused primitive was meant to give.
50 pts · 90 minStart →
ExpertCryptographic weakness
Swapping a JWT to the 'none' algorithm
Break the guarantee a weak or misused primitive was meant to give.
50 pts · 90 minStart →
ExpertCryptographic weakness
The JWT signed with a guessable secret
Break the guarantee a weak or misused primitive was meant to give.
50 pts · 90 minStart →
MasterCryptographic weakness
A padding oracle that reads the ciphertext
Break the guarantee a weak or misused primitive was meant to give.
100 pts · 180 minStart →
MasterCryptographic weakness
Forging a session from a leaked signing key
Break the guarantee a weak or misused primitive was meant to give.
100 pts · 180 minStart →
MasterCryptographic weakness
Nonce reuse that unwinds the keystream
Break the guarantee a weak or misused primitive was meant to give.
100 pts · 180 minStart →