webmedium

AquaCrypt

undutmaning

Task: Flask file sharing app with RSA signature verification, obfuscated verify function, 128-bit weak key. Solution: robots.txt enumeration, source code leak via /admin, deobfuscate verify function, factor small RSA modulus, forge PKCS#1 v1.5 signature.

$ ls tags/ techniques/
source_code_leakrobots_txt_enumerationpython_deobfuscationrsa_small_key_factorizationpkcs1_signature_forgery

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]