$ cat writeup.md…
$ cat writeup.md…
cryptohack
Task: a custom AES whose S-box is GF(2)-affine, so the entire cipher is an affine map E_key(p) = A*p + b over GF(2)^128 with key-independent linear part A. Solution: compute A offline (column i = enc(e_i) XOR enc(0)) from a local instance with any key, query b = enc(0) once on the live target, then recover each ECB flag block p = A^{-1}*(C XOR b) by Gaussian elimination over GF(2).
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar