Fun With RSA — DalCTF 2026

A homemade RSA-CRT signer leaks a correct and a faulted signature of the same message; gcd(s − spz, n) factors n (the Bellcore attack), while the trivial shortcut just recovers the message via s^e mod n — and the XOR ‘protection’ undoes itself.

June 7, 2026 · 8 min · 1517 words · Th3B0yWh0L1v3d