$ cat writeup.md…
$ cat writeup.md…
cryptohack
Task: JWT RS256/HS256 algorithm-confusion (CVE-2016-10555) where the RSA public key is NOT exposed by any route. Solution: recover the RSA modulus n via GCD of two RS256 signatures (s^e - EMSA-PKCS1 pad), rebuild the PKCS#1 'RSA PUBLIC KEY' PEM, and forge an HS256 token signing {admin:true} with the exact PEM bytes (trailing newline included) as the HMAC secret.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar