Browse CTFs New CTF Sign in
Back to Learning Paths
Applied Cryptography & Cryptanalysis
Specialist Wave 2

Applied Cryptography & Cryptanalysis

22.0h estimated 4 Courses

Specialist certification in cryptography covering classical ciphers, symmetric/asymmetric, KDF, JWT, and protocol flaws.

Sign in to enroll

Symmetric Cryptography, KDFs and Credential Attacks

19 cards

Time puzzle

reverse_engineering Difficulty 1–5 30 min

Exploiting Insecure Key Exchange Protocols via Man-in-the-Middle Parameter Manipulation

crypto_symmetric_kdf Difficulty 1–5 30 min

Diffie-Hellman Small Subgroup Confinement Attack: Key Recovery via Order Manipulation

crypto_symmetric_kdf Difficulty 1–5 30 min

Forging Session Tokens via Weak PRNG: Exploiting Insufficient Entropy in Identifiers

crypto_symmetric_kdf Difficulty 1–5 30 min

Blind SQLi login

crypto_symmetric_kdf Difficulty 1–5 30 min

Boolean-based auth flaw

crypto_symmetric_kdf Difficulty 1–5 30 min

Weak password policy exploit

crypto_symmetric_kdf Difficulty 1–5 30 min

Account lockout bypass

crypto_symmetric_kdf Difficulty 1–5 30 min

Breaking Monoalphabetic Substitution Ciphers via Frequency and N-Gram Analysis

encoding_crypto_classical Difficulty 1–5 30 min

Exploiting ECDSA Nonce Reuse to Recover Private Keys via Shared k Values

encoding_crypto_classical Difficulty 1–5 30 min

Linear Congruential Generator Cryptanalysis: Parameter Recovery and State Prediction

encoding_crypto_classical Difficulty 1–5 30 min

Timestamp-Seeded PRNG Exploitation: Predicting and Reproducing Time-Based Random Output

encoding_crypto_classical Difficulty 1–5 30 min

bcrypt Pepper Exposure Analysis: Reconstructing Hash Inputs from Leaked Secret Values

encoding_crypto_classical Difficulty 1–5 30 min

MD5 Collision Generation and Exploitation: Crafting Identical-Hash Inputs for Integrity Bypass

encoding_crypto_classical Difficulty 1–5 30 min

CSRF Token Forgery (Static Artifact): Cross-Origin State-Changing Request Without Token Validation

encoding_crypto_classical Difficulty 1–5 30 min

Non-Expiring Refresh Token (Static Artifact): Indefinite Session Abuse via Missing Token Revocation

encoding_crypto_classical Difficulty 1–5 30 min

X-Forwarded-For Bypass (Static Artifact): Header Manipulation for IP-Based Access Control Defeat

encoding_crypto_classical Difficulty 1–5 30 min

PDF comment stream forensics

crypto_symmetric_kdf Difficulty 1–5 30 min

PDF hidden text layer forensics

crypto_symmetric_kdf Difficulty 1–5 30 min
🏅

CTFFactory Applied Cryptography — Specialist

Specialist credential — awarded upon completion