سبحان الله و بحمده سبحان الله العظيم ❤️

← BACK TO WRITEUPS
RSA picoCTF 400pts EXTREME

Corrupt-Key-2 — Multivariate Coppersmith Attack

Files: private.key (corrupted prime p), msg.enc (128 bytes)

Analysis

The corrupted prime p has 3 blocks of zeroed bytes — 114 unknown bits total (~23% unknown, ~77% known). With >50% bits known, this is a candidate for a multivariate Coppersmith attack based on May & Ritzenhofen (2008).

BlockPositionUnknown Bits
1bits 16-5741 bits
2bits 239-27233 bits
3bits 352-39240 bits

Attack Methodology

Performance

MetricValue
LLL Runtime~313 seconds
Newton Iterations11
Matrix Size120 × 120
Total Time~5.5 minutes

Flag

picoCTF{1d68da1447328c3f11541d076c9c613957d86566}