POSTS

VULNLAB: Share

Share is an easy crypto challenge where the flag is encoded in a polynomial function f(x) = flag + a₁x + a₂x² + a₃x³, with 10 known points (x, f(x)) provided.

VULNLAB: Share
276 words · 2 min

Overview

  • Type Crypto
  • Severity Easy
  • Creator xct
  • Release date 2021 Nov 21

Foothold

Start the instance via Discord and let’s go:

image

We download the challenge file and open it $ cat share.txt:

We have found one of these on each suspect. What secret could they share?

(1,1236845980038787500330644426344609296563053316284551)
(2,7455293105561248663255667475692465968758017231599185)
(3,23363661639997223568427003214341847967175177982492279)
(4,53544146072410073968338004140825466260678170070281877)
(5,102578940891863161615482022753676031818130627996286023)
(6,175050240587419848262352411551426255608396186261822761)
(7,275540239648143495661442523032608848600338479368210135)
(8,408631132563097465565245709695756521762821141816766189)
(9,578905113821345119726255324039401986064707808108808967)
(10,790944377911949819896964718562077952474862112745656513)

Apparently they used this code to generate these numbers:

from random import randint
from Crypto.Util.number import *

flag = bytes_to_long(b"VL{...}")
flag_len = len(str(flag))

def getnum():
    s = ''
    for i in range(flag_len):
        s = s + str(randint(0,9))
    return int(s)

a1 = getnum()
a2 = getnum()
a3 = getnum()

f = lambda x: flag + a1*x + a2*(x**2) + a3*(x**3)
for i in range(1,10+1,1):
    print(f"({i},{f(i)})")

After analysed the file, we can easily create a python script solve.py to resolve it:

import sympy as sp

# Define the variables a3, a2, a1, and flag
flag, a1, a2, a3 = sp.symbols('flag a1 a2 a3')

# Define the equations based on your given values
eq1 = sp.Eq(flag + a1*1 + a2*1**2 + a3*1**3, 1236845980038787500330644426344609296563053316284551)
eq2 = sp.Eq(flag + a1*2 + a2*2**2 + a3*2**3, 7455293105561248663255667475692465968758017231599185)
eq3 = sp.Eq(flag + a1*3 + a2*3**2 + a3*3**3, 23363661639997223568427003214341847967175177982492279)
eq4 = sp.Eq(flag + a1*4 + a2*4**2 + a3*4**3, 53544146072410073968338004140825466260678170070281877)

# Solve the system of equations
solution = sp.solve([eq1, eq2, eq3, eq4], (flag, a1, a2, a3))

# Print the solution
print(solution)

# Get the flag value
flag_value = solution[flag]

# Convert the flag back to bytes using long_to_bytes
from Crypto.Util.number import long_to_bytes
flag_bytes = long_to_bytes(int(flag_value))

print(f"Flag (bytes): {flag_bytes}")

Then install the module Crypto and execute it:

$ sudo apt install python3-pycryptodome
$ python3 solve.py
Flag: VL{Sh4R1nG_1s_C4r1nG}

Found the flag VL{Sh4R1nG_1s_C4r1nG}