OFFSEC Wiki

Exploits related to Cryptography

Algorithm

AES (Advanced Encryption Standard)
AES-CBC Bit Flipping Attack
AES-CBC Padding Oracle Attack
AES-ECB Padding Attack
Ansible Vault Secret
Atbash Cipher
Base32, Base64
Caesar Cipher
Camellia Cipher
Certificates
Cryptography
Diffie-Hellman Key Exchange
ECC (Elliptic Curve Cryptography)
ECDSA (Elliptic Curve Digital Signature Algorithm)
Fernet
GPG (GNU Privacy Guard)
HMAC
KDBX Files
Length Extension Attack
MD4, MD5
Multi-Tap Cipher
NTLM, NTLMv2
PEM (Privacy Enhanced Mail)
PGP (Pretty Good Privacy)
PKCS (Public-Key Cryptography Standards)
RAR (Roshal Archive)
RIPEMD
ROT13, ROT47
RPNG (Pseudo Random Number Generator) Guessing
RSA (Rivest Shamir Adleman)
SHA1 Hash Collision Attack
SHA1, SHA256, SHA512
Transposition Cipher
Vigenere Cipher

Key Derivation Function

Bcrypt
PBKDF2
Scrypt

Tool

John the Ripper

Math

Chinese Remainder Theorem
Exponentiation
GCD (Greatest Common Divisor)
Modular Congruence
Quadratic Residue

Bit Wise Operation

AND Bitwise Operations
OR Bitwise Operations
Shift Bitwise Operations
XOR Bitwise Operations

Conversion

Convert Binary to Int in Python
Convert Bytes to Hex in Python
Convert Bytes to Int in Python
Convert Bytes to Matrix in Python
Convert Bytes to String in Python
Convert Character to Binary in Python
Convert Character to Unicode in Python
Convert Hex to Bytes in Python
Convert Hex to Int in Python
Convert Int to Binary in Python
Convert Int to Bytes in Python
Convert Int to Hex in Python
Convert Int to String in Python
Convert Matrix to Bytes in Python
Convert String to Binary in Python
Convert String to Bytes in Python
Convert String to Int in Python
Convert Unicode to Character in Python
Zero Padding in Python

Others

Length Extension Attack

Last modified: 2023-07-27

Cryptography

Exploitation

We can exploit the vulnerability with hash_extender.

References

  • https://en.wikipedia.org/wiki/Length_extension_attack
  • https://github.com/iagox86/hash_extender

Tools by Muhammd

RedTeam Repos

Automatic PenTest Scripts

AutoRecon

Auto reconnaissance CLI.

PenTest Tools

PenTest Tools

Disclaimer Privacy Policy

GitHub Twitter