$ cat writeup.md…
$ cat writeup.md…
cryptohack
Task: a CBC padding oracle on CryptoHack that LIES — it XORs the true PKCS#7 validity bit with rng.random()>0.4, so a valid pad reads True only 40% of the time vs 60% for invalid, under a hard 12000-query budget. Solution: exploit the hex-string plaintext (16 candidates/byte, exactly one valid) to turn each byte into a 1-of-16 best-arm identification problem, then use log-likelihood-ratio scoring with LUCB-style adaptive allocation over a global budget pool to recover all 32 bytes in ~9400 queries.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar