Angry Shamir — DalCTF 2026

An RSA modulus that looks 2054-bit-strong is actually 67 × q — a tiny prime factor makes it trivially factorable (FactorDB / trial division), reconstructing the private key and decrypting the flag.

June 6, 2026 · 4 min · 824 words · Th3B0yWh0L1v3d