cryptomedium

Гран-при (Grand Prix)

duckerz

Task: Flask racing game with sha256(secret || message) signature scheme. Solution: Hash Length Extension Attack to forge hacker228 bot signatures and disqualify all competitors using parameter pollution.

$ ls tags/ techniques/
signature_forgeryhash_length_extension_attackparameter_override

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]