Cryptography
My notes on cryptography for CTF, from the math foundations through classical ciphers, symmetric and public-key crypto, to the real attacks you see in challenges. Most crypto challenges are not about breaking AES or RSA, they are about finding where someone used them wrong.
The labs are small challenges with a working solve script. Everything is for learning, CTFs, and systems you are allowed to test.
Crypto · Getting Started
| # | Lesson |
|---|---|
| 0.1 | Cryptography Goals and Threat Models |
| 0.2 | Kerckhoffs’s Principle and Ethics |
| 0.3 | Setting Up a Crypto Lab |
Crypto · Math Foundations
Crypto · Classical Ciphers
| # | Lesson |
|---|---|
| 2.1 | Encoding Is Not Encryption |
| 2.2 | Caesar, Vigenere and Frequency Analysis |
| 2.3 | Rail Fence, Playfair, and Enigma |
Crypto · XOR and OTP
| # | Lesson |
|---|---|
| 3.1 | Single-Byte and Multi-Byte XOR |
| 3.2 | One-Time Pad and Key Reuse |
| 3.3 | Lab on Breaking Repeating-Key XOR |
Crypto · Symmetric Encryption
Crypto · Hashes and MACs
| # | Lesson |
|---|---|
| 5.1 | Hash Functions, MD5/SHA, and Collisions |
| 5.2 | Length Extension Attack |
| 5.3 | MAC, HMAC, and Timing Attacks on Tag Comparison |
| 5.4 | Password Storage and Cracking with hashcat |
Crypto · RSA
Crypto · Diffie-Hellman
Crypto · Elliptic Curves
| # | Lesson |
|---|---|
| 8.1 | ECC Basics, ECDH and ECDSA |
| 8.2 | ECDSA Private Key Recovery from Nonce Reuse |
| 8.3 | Weak Elliptic Curves |
Crypto · Randomness
Crypto · Crypto in Practice
| # | Lesson |
|---|---|
| 10.1 | TLS and PKI Certificate Chains |
| 10.2 | Z3 and SMT for Crypto |
| 10.3 | Post-Quantum Cryptography Basics |