$ cat writeup.md…
$ cat writeup.md…
cryptohack
Task: AES-GCM web oracle reuses a fixed nonce across encryptions and grants the flag for any valid tag on the message 'give me the flag'. Solution: Joux's Forbidden Attack — two same-nonce (ct,tag) pairs give a polynomial in the GHASH key H over GF(2^128); factor it (Cantor-Zassenhaus) to recover H, leak E_K(J0), then forge a valid tag for the forbidden ciphertext.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar