Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
perl-CryptX — Perl cryptographic toolkit providing symmetric ciphers, AEAD modes, hash functions, MACs, public-key cryptography, key derivation, and secure random generation via the bundled LibTomCrypt library. | Kitploit
Tools/GitHubGitHub/dcit/perl-cryptx
Password CrackingEncryption/Decryption ToolsHash AnalysisCryptographyUtilities & FrameworksAuthentication
GitHubdcit/perl-cryptx

perl-CryptX

Perl cryptographic toolkit providing symmetric ciphers, AEAD modes, hash functions, MACs, public-key cryptography, key derivation, and secure random generation via the bundled LibTomCrypt library.

View Repository
41262129 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website

NAME

CryptX - Cryptographic toolkit

SYNOPSIS

CryptX is the distribution entry point. In normal code, load one of the concrete modules listed below.

## one-shot hashing
use Crypt::Digest qw(digest_data_hex);
my $sha256 = digest_data_hex('SHA256', 'hello world');

## classic AES-CBC encryption with padding
use Crypt::Mode::CBC;
my $cbc = Crypt::Mode::CBC->new('AES');
my $iv = random_bytes(16); # 16-byte AES block-size IV
my $cbc_ciphertext = $cbc->encrypt('hello world', $key, $iv);

## authenticated encryption (AEAD) with AES
use Crypt::AuthEnc::GCM qw(gcm_encrypt_authenticate);
my $key = random_bytes(32);   # 32-byte AES-256 key
my $nonce = random_bytes(12); # 12-byte unique nonce
my ($ciphertext, $tag) = gcm_encrypt_authenticate('AES', $key, $nonce, 'header', 'hello world');

## message authentication
use Crypt::Mac::HMAC qw(hmac_hex);
my $mac = hmac_hex('SHA256', $key, 'hello world');

## secure random data + UUID helpers
use Crypt::PRNG qw(random_bytes random_string);
use Crypt::Misc qw(random_v4uuid random_v7uuid);
my $salt = random_bytes(16);
my $token = random_string(24);
my $uuid4 = random_v4uuid();
my $uuid7 = random_v7uuid();

## classic password-based key derivation
use Crypt::KeyDerivation qw(pbkdf2);
my $dk = pbkdf2('password', $salt, 100_000, 'SHA256', 32);

## bare stream cipher (authenticate separately)
use Crypt::Stream::ChaCha;
my $stream = Crypt::Stream::ChaCha->new($key, $nonce);
my $stream_ciphertext = $stream->crypt('hello world');

## modern signatures
use Crypt::PK::Ed25519;
my $signer = Crypt::PK::Ed25519->new->generate_key;
my $sig = $signer->sign_message('hello world');
my $ok = $signer->verify_message($sig, 'hello world');

## key agreement
use Crypt::PK::X25519;
my $alice = Crypt::PK::X25519->new->generate_key;
my $bob = Crypt::PK::X25519->new->generate_key;
my $shared_secret = $alice->shared_secret($bob);

DESCRIPTION

Perl cryptographic modules built on the bundled LibTomCrypt library. The distribution also includes Math::BigInt::LTM, a Math::BigInt backend built on the bundled LibTomMath library used internally by LibTomCrypt.

This module mainly serves as the top-level distribution/documentation page. For actual work, use one of the concrete modules listed below.

Algorithm Selection Guide

Authenticated Encryption (AEAD)

For new designs, prefer authenticated encryption (AEAD) over bare cipher modes:

  • ChaCha20-Poly1305 (Crypt::AuthEnc::ChaCha20Poly1305) - Fast, constant-time, widely deployed (TLS 1.3, WireGuard, SSH). Use this as the default AEAD choice.
  • XChaCha20-Poly1305 (Crypt::AuthEnc::XChaCha20Poly1305) - Extended 24-byte nonce variant. Prefer over ChaCha20-Poly1305 when nonces are generated randomly.
  • AES-GCM (Crypt::AuthEnc::GCM) - The standard AEAD mode for AES. Hardware-accelerated on modern CPUs. Requires unique nonces; nonce reuse breaks the security entirely.
  • AES-SIV (Crypt::AuthEnc::SIV) - Deterministic AEAD, nonce-misuse resistant. Slightly slower but safer when nonce uniqueness cannot be guaranteed.
  • AES-GCM-SIV (Crypt::AuthEnc::GCMSIV) - Nonce-misuse-resistant AEAD (RFC 8452). Faster than AES-SIV; pick this when you need GCM-like performance with nonce-reuse safety.
  • AES-OCB (Crypt::AuthEnc::OCB) - Very fast single-pass AEAD. Check patent status for your jurisdiction.
  • AES-EAX (Crypt::AuthEnc::EAX) - Two-pass AEAD based on CTR+OMAC. No patents, no nonce-length restrictions.
  • AES-CCM (Crypt::AuthEnc::CCM) - Used in WiFi (WPA2) and Bluetooth. Requires knowing the plaintext length in advance.

Cryptographically Secure Randomness and UUIDs

  • Random bytes / strings (Crypt::PRNG) - Use this for salts, keys, nonces, tokens, and any other secret random values. The functional helpers random_bytes, random_bytes_hex, random_bytes_b64, random_bytes_b64u, random_string, and random_string_from cover most use cases. The OO API and the algorithm-specific wrappers (Crypt::PRNG::ChaCha20, Crypt::PRNG::Fortuna, etc.) are mainly for deterministic streams or interoperability with a specific PRNG.
  • UUIDs ("random_v4uuid" in Crypt::Misc, "random_v7uuid" in Crypt::Misc) - Use random_v4uuid for opaque random identifiers. Use random_v7uuid when you want roughly time-ordered identifiers that sort by creation time at millisecond granularity. UUIDs are identifiers, not replacements for secret random bytes.

Stream Ciphers

Stream ciphers encrypt data byte-by-byte without block padding. For most applications prefer an AEAD mode (see above) which bundles encryption with authentication. Use bare stream ciphers only when you handle authentication separately.

  • ChaCha (Crypt::Stream::ChaCha) - The default stream cipher choice. Same core as ChaCha20-Poly1305 without the built-in MAC.
  • XChaCha (Crypt::Stream::XChaCha) - Extended 24-byte nonce variant of ChaCha. Prefer when nonces are generated randomly.
  • Salsa20 / XSalsa20 (Crypt::Stream::Salsa20, Crypt::Stream::XSalsa20) - Predecessor of ChaCha. Prefer ChaCha for new designs; Salsa20 only for interoperability (e.g. NaCl/libsodium).
  • RC4 (Crypt::Stream::RC4) - Broken; do not use for new designs. Provided for legacy interoperability only.
  • Rabbit, Sober128, Sosemanuk (Crypt::Stream::Rabbit, Crypt::Stream::Sober128, Crypt::Stream::Sosemanuk) - Niche ciphers from the eSTREAM portfolio. Use ChaCha unless a specific protocol requires one of these.

Block Cipher Modes (without authentication)

Use these only when authentication is handled separately or not needed:

  • CTR (Crypt::Mode::CTR) - Turns a block cipher into a stream cipher. Parallelizable.
  • CBC (Crypt::Mode::CBC) - Classic mode, needs padding. Prefer CTR or an AEAD mode.
  • ECB (Crypt::Mode::ECB) - Insecure for most uses. Each block encrypted independently.
Download Tool