$ cat writeup.md…
$ cat writeup.md…
cryptohack
Task: RSA whose primes are generated as p = k*M + (e^a mod M) with M = primorial(40) — the Infineon ROCA structure (CVE-2017-15361) — and the flag is PKCS#1 OAEP encrypted. Solution: ROCA primes are factorable in practice via the Coppersmith/Bernstein-Heninger attack that exploits the small residue space mod M; here the modulus is only 511-bit so factordb already holds p,q, after which we reconstruct the private key and PKCS#1 OAEP-decrypt the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar