b00t2root CTF: cuz rsa is lub [RSA Cryptography]

John Hammond · Intermediate ·🔐 Cybersecurity ·7y ago

Key Takeaways

The video demonstrates how to solve an RSA cryptography challenge, specifically the 'cuz rsa is lub' challenge from the b00t2root CTF, using Python and the crypto library to calculate the private key and decrypt the message.

Full Transcript

[Music] what is going on everybody my name is John Hammond welcome back from the YouTube video we're looking at two roots ETF moving to the cryptography category this is the challenge because RSA is love and it just gives us this prompt for RSA text so I would copy link and download it if I had W get accessible to me except it's a stupid Google Doc so we're just gonna work with that we can go ahead and actually create a API for this I'm gonna crank this up in sublime text you can see a little bit better use your bin environment Python etc etc well paste these in because we have the variables that we need here so I have done many videos on RSA you can track on another one especially when we cover it in Pico is a little bit more there that actually discusses how it's happening how it happens behind the scenes you look at the Wikipedia article you look at the math etc but in this case we know what we're gonna do in the and I'm just gonna run through the process of doing it because that's what our say packed lis is it's one that once you know it it's like okay there are a couple of variations there are a couple tricks but the classic RSA is quick and easy to run through so we have N and if we can check out factor DB if we have that accessible trying to actually f11 there and move out of this page but it's taken some time hang on so in fact DB will paste in that N and we've got P and Q there if that didn't have it which I think originally when we tried this challenge the P and Q weren't present you can run the RSA CTF tool on it and that's available on github and around so I don't know why that's not giving me the full value that's kind of annoying 3 ^ 178 x 22 let's put that in there and see if it see if it goes and this one also that will give me the value that's very weird whatever q okay so now I've got P and Q and we can determine fee right or the totient so because P and Q are both primes the property allows us to find fee as just P minus 1 times Q minus 1 and that's simple and easy so now we can go ahead and do the modular inverse to determine D so I'm gonna do this with from crypto a util dot number import inverse and I believe it's D equals inverse e Phi I'm pretty sure I might have that the other way around but do we have D does that work for us we do have D all right so we can now go ahead and try and calculate M because now that we have the private key D we should be able to raise C to the power of D all mod N and that should be M so we can go ahead and say as a number now let's go ahead and make that hex so let's hex hex that okay and that looks like regular readable characters hopefully to negative 1 so that's all cut off and then we can go ahead and decode that so let's decode hex and know if it print needs to work maybe I had print you know let's just remove our parentheses because that's annoying and I forgot to put hex in that in strings there we go boot to root RSA can be vulnerable so that should be the flag and that's very very simple just know the procedure classical or essay and you can crank out the flag no I had to do that off the top your head is pretty good I don't think there are too many steps in RSA and often times once you've got it down pat you can just kind of hit the I believe button there so boot to root RSA can be vulnerable that is the flag let's go ahead and submit it and 50 points on the table great thank you guys so much for watching if you like this video please do like comment and subscribe join the discord server there is a link in the description it is a really cool place because it has a ton of smart people way smarter than me and we're all willing to tackle a capital flag challenge we're all about learning it's all about cybersecurity it's cool it's cool in classic shout-out to r4j he tackled us before I did it's just Ridge '''l RSA challenge but I know he just jumps in and I'm grateful for those that are willing that can attack these with me you're all part of the community you're all part of the family see you later everybody [Music] [Music] [Music] [Music] [Music] [Music] [Music] [Music] you

Original Description

If you would like to support me, please like, comment & subscribe, and check me out on Patreon: https://patreon.com/johnhammond010 E-mail: johnhammond010@gmail.com PayPal: http://paypal.me/johnhammond010 GitHub: https://github.com/JohnHammond Site: http://www.johnhammond.org Twitter: https://twitter.com/_johnhammond
Watch on YouTube ↗ (saves to browser)
Sign in to unlock AI tutor explanation · ⚡30

Playlist

Uploads from John Hammond · John Hammond · 0 of 60

← Previous Next →
1 Code Commentaries? PHP to JavaScript in Bash and PHP!
Code Commentaries? PHP to JavaScript in Bash and PHP!
John Hammond
2 Tutorials? MySQL connection with PHP and Bash!
Tutorials? MySQL connection with PHP and Bash!
John Hammond
3 Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
John Hammond
4 JavaScript Splits The URL!
JavaScript Splits The URL!
John Hammond
5 HTML Tables in Python!
HTML Tables in Python!
John Hammond
6 HTML, Net Shares, GML!
HTML, Net Shares, GML!
John Hammond
7 Python 08 Programming Style and Comments
Python 08 Programming Style and Comments
John Hammond
8 Python 26 Object Oriented Programming
Python 26 Object Oriented Programming
John Hammond
9 75 Python Tutorials, Out Now!
75 Python Tutorials, Out Now!
John Hammond
10 Batch 14 Mathematical Expressions
Batch 14 Mathematical Expressions
John Hammond
11 Batch 85 Array Append
Batch 85 Array Append
John Hammond
12 Batch 86 Array Count
Batch 86 Array Count
John Hammond
13 Batch 87 Array Index
Batch 87 Array Index
John Hammond
14 Batch 88 Array Insert
Batch 88 Array Insert
John Hammond
15 Batch 89 Array Remove
Batch 89 Array Remove
John Hammond
16 Batch 90 Array Reverse
Batch 90 Array Reverse
John Hammond
17 Python [colorama] 00 Installing on Linux
Python [colorama] 00 Installing on Linux
John Hammond
18 Python [colorama] 09 Cursor Position
Python [colorama] 09 Cursor Position
John Hammond
19 Python [hashlib] 02 Algorithms
Python [hashlib] 02 Algorithms
John Hammond
20 Python 00 Installing IDLE on Linux
Python 00 Installing IDLE on Linux
John Hammond
21 Python [pygame] 11 Rectangular Collision Detection
Python [pygame] 11 Rectangular Collision Detection
John Hammond
22 Python [pygame] 12 Platforming Rectangular Collision Resolution
Python [pygame] 12 Platforming Rectangular Collision Resolution
John Hammond
23 Python [XML-RPC] 01 Research
Python [XML-RPC] 01 Research
John Hammond
24 Python [pyenchant] 03 Personal Word Lists
Python [pyenchant] 03 Personal Word Lists
John Hammond
25 FancyURLopener Authentication and User-Agent [urllib] 03
FancyURLopener Authentication and User-Agent [urllib] 03
John Hammond
26 Python 04: PEP8 Coding
Python 04: PEP8 Coding
John Hammond
27 Python Challenge! 17 COOKIES
Python Challenge! 17 COOKIES
John Hammond
28 Google CTF 2016: Ernst Echidna
Google CTF 2016: Ernst Echidna
John Hammond
29 Google CTF 2016: Spotted Quoll
Google CTF 2016: Spotted Quoll
John Hammond
30 Google CTF 2016: Can you Repo It?
Google CTF 2016: Can you Repo It?
John Hammond
31 Google CTF 2016: No Big Deal
Google CTF 2016: No Big Deal
John Hammond
32 Google CTF 2016: In Recorded Conversation
Google CTF 2016: In Recorded Conversation
John Hammond
33 Homemade CTF Challenge: 01 "Orchestra"
Homemade CTF Challenge: 01 "Orchestra"
John Hammond
34 Homemade CTF Challenge: 02 "Bae's Base"
Homemade CTF Challenge: 02 "Bae's Base"
John Hammond
35 Homemade CTF Challenge: 03 "Web Hunt"
Homemade CTF Challenge: 03 "Web Hunt"
John Hammond
36 Homemade CTF Challenge: 04 "UPX"
Homemade CTF Challenge: 04 "UPX"
John Hammond
37 Homemade CTF Challenge: 05 "The Assumption Song"
Homemade CTF Challenge: 05 "The Assumption Song"
John Hammond
38 Homemade CTF Challenge: 06 "A Brisk Stroll"
Homemade CTF Challenge: 06 "A Brisk Stroll"
John Hammond
39 Homemade CTF Challenge: 06 "I lost my password!"
Homemade CTF Challenge: 06 "I lost my password!"
John Hammond
40 web25 :: Mr. Robot : EKOPARTY CTF 2016
web25 :: Mr. Robot : EKOPARTY CTF 2016
John Hammond
41 web50 : RFC 7230 :: EKOPARTY CTF 2016
web50 : RFC 7230 :: EKOPARTY CTF 2016
John Hammond
42 misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
John Hammond
43 Hack The Vote 2016 CTF: Sander's Fan Club [web100]
Hack The Vote 2016 CTF: Sander's Fan Club [web100]
John Hammond
44 Hack The Vote 2016 CTF Warpspeed [forensics150]
Hack The Vote 2016 CTF Warpspeed [forensics150]
John Hammond
45 Juniors CTF 2016 :: Black Suprematic Square
Juniors CTF 2016 :: Black Suprematic Square
John Hammond
46 Juniors CTF 2016 :: Six Strange Tales
Juniors CTF 2016 :: Six Strange Tales
John Hammond
47 Juniors CTF 2016 :: Lost Code
Juniors CTF 2016 :: Lost Code
John Hammond
48 Juniors CTF 2016 :: Here Goes!
Juniors CTF 2016 :: Here Goes!
John Hammond
49 Juniors CTF 2016 :: Southern Cross
Juniors CTF 2016 :: Southern Cross
John Hammond
50 Juniors CTF 2016 :: Clone Attack
Juniors CTF 2016 :: Clone Attack
John Hammond
51 Juniors CTF 2016 :: Dirty Repo
Juniors CTF 2016 :: Dirty Repo
John Hammond
52 Juniors CTF 2016 :: Hackers Blog
Juniors CTF 2016 :: Hackers Blog
John Hammond
53 Juniors CTF 2016 :: Voting!!!
Juniors CTF 2016 :: Voting!!!
John Hammond
54 Juniors CTF 2016 :: The Good, The Bad and The Junkman
Juniors CTF 2016 :: The Good, The Bad and The Junkman
John Hammond
55 Juniors CTF 2016 :: Stop Thief!
Juniors CTF 2016 :: Stop Thief!
John Hammond
56 Juniors CTF 2016 :: ROFL
Juniors CTF 2016 :: ROFL
John Hammond
57 Juniors CTF 2016 :: Restriced Area
Juniors CTF 2016 :: Restriced Area
John Hammond
58 Juniors CTF 2016 :: Oh SSH!
Juniors CTF 2016 :: Oh SSH!
John Hammond
59 HackCon CTF 2017 TRIVIA and BONUS Challenges
HackCon CTF 2017 TRIVIA and BONUS Challenges
John Hammond
60 HackCon CTF 2017 "Bacche" Challenges
HackCon CTF 2017 "Bacche" Challenges
John Hammond

The video teaches how to solve an RSA cryptography challenge by calculating the private key and decrypting the message using Python and the crypto library. The challenge is from the b00t2root CTF and requires understanding of RSA algorithm and modular arithmetic.

Key Takeaways
  1. Calculate N and factorize it using factorDB or RSA CTF tool
  2. Determine P and Q values
  3. Calculate the totient function (phi)
  4. Compute the modular inverse to find the private key (D)
  5. Raise C to the power of D mod N to find the decrypted message (M)
  6. Convert M to hex and decode it to obtain the flag
💡 The RSA algorithm can be vulnerable if the private key is not properly secured, and calculating the private key requires factorizing the modulus N.

Related Reads

Up next
How To Delete Your Data From The Internet | Privacy Bee Review & Tutorial 2026
Tutorial Stack
Watch →