🎡 SICTF2023 Round2
小位数直接当作已知数(爆破可出);Coppersmith’s Short-pad Attack & Related Message Attack(Franklin-Reiter攻击);MTP攻击;small_roots方法的epsilon参数
🫐 WMCTF2023
一元copper攻击;gift = int(bin(P ^ (Q >> offset))[2+offset:],2)hensel分解出的p或者回溯;Right-to-Left 算法,Left-to-Right 算法,rsa差分攻击
🎯 Franklin–Reiter相关消息攻击
Franklin–Reiter related-message attack,hitcon 2014 rsaha,N1CTF 2018 rsa_padding
⛈️ DASCTF 2023 & 0X401七月复现
光滑数,Franklin-Reiter相关消息攻击,copper求t,groebner_basis(),Hensel‘s Lifting Lemma