$ cat writeup.md…
$ cat writeup.md…
UIUCTF 2026
Task: Decrypt multilingual literary excerpts hidden by fresh rune-based monoalphabetic substitutions. Solution: identify each Gutenberg source from its redacted attribution mask, then locate the excerpt through exact word-pattern isomorphism.
$ cat /etc/rate-limit
Rate limit reached (20 reads/hour per IP). Showing preview only — full content returns at the next hour roll-over.
No separate organizer description was preserved in the task artifacts. The interactive service supplied the rules summarized below.
The TLS service ran 20 rounds. In each round it encrypted a multilingual literary excerpt using a fresh monoalphabetic mapping from plaintext letters to Unicode runes while retaining spaces and punctuation. It allowed five full-plaintext guesses, and an incorrect guess disclosed only the number of correctly decrypted symbols. Solving more than 70% of the rounds was required.
The server was reached at rune-decryptor.chal.uiuc.tf:1337 and required a kCTF proof of work before the first round.
The word “decryptor” initially suggested an RSA or padding oracle, but the live protocol immediately disproved that interpretation: this was a direct monoalphabetic-substitution problem. The score returned after a failed guess was a single weighted Hamming total over the whole paragraph. Five such scalar observations cannot recover an arbitrary fresh key containing roughly two dozen independent mappings. At best, that feedback could distinguish a few nearly complete candidates.
Direct substitution cryptanalysis was also unattractive because every round used another language and a new key:
The decisive observation was outside the ciphertext. Under every paragraph, the service printed a redacted attribution derived from Title -- Authors. Alphanumeric characters became block glyphs, but spaces, punctuation, character counts, and the truncation point remained visible. This was a strong structural fingerprint.
...
$ grep --similar