Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
crypto-attacks — Python implementations of cryptographic attacks and utilities. | Kitploit
Tools/GitHubGitHub/jvdsn/crypto-attacks
CryptographyCTFPapers & ResearchLearning & Education
GitHubjvdsn/crypto-attacks

crypto-attacks

Python implementations of cryptographic attacks and utilities.

View Repository
1.3k1457 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Introduction

Python implementations of cryptographic attacks and utilities.

Requirements

  • SageMath with Python 3.9
  • PyCryptodome

You can check your SageMath Python version using the following command:

root@kitploit:~
$ sage -python --version
Python 3.9.0

If your SageMath Python version is older than 3.9.0, some features in some scripts might not work.

Usage

Unit tests are located in the test directory and can be executed using the unittest module or using pytest. This should not take very long, perhaps a few minutes depending on your machine.

To run a specific attack, you must add the code to the proper file before executing it.

Example

For example, you want to attack RSA using the Boneh-Durfee attack, with the following parameters (taken from test_rsa.py):

root@kitploit:~
N = 88320836926176610260238895174120738360949322009576866758081671082752401596826820274141832913391890604999466444724537056453777218596634375604879123818123658076245218807184443147162102569631427096787406420042132112746340310992380094474893565028303466135529032341382899333117011402408049370805729286122880037249
e = 36224751658507610673165956970793195381480143363550601971796688201449789736497322700382657163240771111376677180786660893671085854060092736865293791299460933460067267613023891500397200389824179925263846148644777638774319680682025117466596019474987378275216579013846855328009375540444176771945272078755317168511

You add the following code at the bottom of the boneh_durfee.py file:

root@kitploit:~
import logging

# Some logging so we can see what's happening.
logging.basicConfig(level=logging.DEBUG)

N = 88320836926176610260238895174120738360949322009576866758081671082752401596826820274141832913391890604999466444724537056453777218596634375604879123818123658076245218807184443147162102569631427096787406420042132112746340310992380094474893565028303466135529032341382899333117011402408049370805729286122880037249
e = 36224751658507610673165956970793195381480143363550601971796688201449789736497322700382657163240771111376677180786660893671085854060092736865293791299460933460067267613023891500397200389824179925263846148644777638774319680682025117466596019474987378275216579013846855328009375540444176771945272078755317168511
p_bits = 512
delta = 0.26

p, q = attack(N, e, p_bits, delta=delta, m=3)
assert p * q == N
print(f"Found {p = } and {q = }")

Then you can simply execute the file using Sage. It does not matter where you execute it from, the Python path is automagically set (you can also call the attacks from other Python files, but then you'll have to fix the Python path yourself):

root@kitploit:~
[crypto-attacks]$ sage -python attacks/rsa/boneh_durfee.py
INFO:root:Trying m = 3, t = 1...
DEBUG:root:Generating shifts...
DEBUG:root:Creating a lattice with 11 shifts (order = 'invlex', sort_shifts_reverse = False, sort_monomials_reverse = False)...
DEBUG:root:Reducing a 11 x 11 lattice...
DEBUG:root:Reconstructing polynomials (divide_original = True, modulus_bound = False, divide_gcd = True)...
DEBUG:root:Polynomial at row 8 is constant, ignoring...
DEBUG:root:Reconstructed polynomial has gcd 1312232632720549890113031660369306919929075823824696839212183146130434668203517349691252841557097914064120078389640402109017308806168467714230057403815071456395553717020189622129706447677967264344568789118172311850383406340547579993263937406518074980025897726255316031512238322022839331135299265704052474541497687419350763703993630899191179705015113329644753599872380152055902238937889027950089072598069861391599563222633064848996619752054685734260976071760984100109990150069201501748622288840900421607423175114026653242500476408861976142751384898489130281755466581359057847077651502734556259387442296763474369957121 with polynomial at 8, dividing...
DEBUG:root:Reconstructed 10 polynomials
DEBUG:root:Computing pairwise gcds to find trivial roots...
DEBUG:root:Using Groebner basis method to find roots...
DEBUG:root:Sequence length: 10, Groebner basis length: 1
DEBUG:root:Sequence length: 9, Groebner basis length: 1
DEBUG:root:Sequence length: 8, Groebner basis length: 1
DEBUG:root:Sequence length: 7, Groebner basis length: 2
DEBUG:root:Found Groebner basis with length 2, trying to find roots...
Found p = 7866790440964395011005623971351568677139336343167390105188826934257986271072664643571727955882500173182140478082778193338086048035817634545367411924942763 and q = 11227048386374621771175649743442169526805922745751610531569607663416378302561807690656370394330458335919244239976798600743588701676542461805061598571009923

The parameters m and t as shown in the output log deserve special attention. These parameters are used in many lattice-based (small roots) algorithms to tune the lattice size. Conceptually, m (sometimes called k) and t represent the number of "shifts" used in the lattice, which is roughly equal or proportional to the number of rows. Therefore, increasing m and t will increase the size of the lattice, which also increases the time required to perform lattice reduction (currently using LLL). On the other hand, if m and t are too low, it is possible that the lattice reduction will not result in appropriate vectors, therefore wasting the time spent reducing. Hence, this is a trade-off.

In the current version of the project, m must always be provided by the user (the default value is set to 1). t can, in some cases, be computed based on the specific small roots method used by the attack. However it can still be tweaked by the user. In general, there are two ways to use these kinds of parameters:

  • Implement a loop which starts at m = 1 until an answer is found (example below). This is a simple approach, but risks wasting time on futile computations with too small lattices.
root@kitploit:~
m = 1
while True:
    res = attack(..., m=m)
    if res is not None:
        # The attack succeeded!
        break
    m += 1
  • Implement a debug version of the attack you're trying to use (with known results), and determine the m value which results in good lattice vectors. Then directly call the attack method with the correct m value.

Implemented attacks

Approximate Common Divisor

  • Multivariate polynomial attack 1
  • Orthogonal based attack 2
  • Simultaneous Diophantine approximation attack 3

CBC

  • Bit flipping attack
  • IV recovery attack
  • Padding oracle attack

CBC + CBC-MAC

  • Key reuse attack (encrypt-and-MAC)
  • Key reuse attack (encrypt-then-MAC)
  • Key reuse attack (MAC-then-encrypt)

CBC-MAC

  • Length extension attack

CTR

  • Bit flipping attack
  • CRIME attack
  • Separator oracle attack

ECB

  • Plaintext recovery attack
  • Plaintext recovery attack (harder variant)
  • Plaintext recovery attack (hardest variant)

Elliptic Curve Cryptography

  • ECDSA nonce reuse attack
  • Frey-Ruck attack 4
  • MOV attack 5
  • Parameter recovery
  • Singular curve attack
  • Smart's attack (with curves over extension fields) 6 7

ElGamal Encryption

  • Nonce reuse attack
  • Unsafe generator attack

ElgGamal Signature

  • Bleichenbacher's attack
  • Khadir's attack
  • Nonce reuse attack

Factorization

  • Base conversion factorization
  • Branch and prune attack 8
  • Complex multiplication (elliptic curve) factorization 9
  • Coppersmith factorization
  • Fermat factorization
  • Ghafar-Ariffin-Asbullah attack 10
  • Implicit factorization 11

GCM

  • Forbidden attack 16

Hidden Number Problem

With applications to partial (EC)DSA nonce exposure.

  • Extended hidden number problem 17
  • Fourier analysis attack
  • Lattice-based attack

IGE

  • Padding oracle attack

Knapsack Cryptosystems

  • Low density attack 18

Linear Congruential Generators

  • LCG parameter recovery
  • Truncated LCG parameter recovery 19
  • Truncated LCG state recovery 20

Learning With Errors

  • Arora-Ge attack 21
  • Blum-Kalai-Wasserman attack
  • Lattice reduction attack

Mersenne Twister

  • State recovery

One-time Pad

  • Key reuse

Pseudoprimes

  • Generating Miller-Rabin pseudoprimes 22

RC4

  • Fluhrer-Mantin-Shamir attack

RSA

  • Bleichenbacher's attack 23
  • Bleichenbacher's signature forgery attack
  • Boneh-Durfee attack 24
  • Cherkaoui-Semmouni's attack 25
  • Common modulus attack
  • CRT fault attack
  • d fault attack
  • Desmedt-Odlyzko attack (selective forgery)

Shamir's Secret Sharing

  • Deterministic coefficients
  • Share forgery

Other interesting implementations

  • Adleman-Manders-Miller root extraction method 40
  • Fast CRT using divide-and-conquer
  • Fast modular inverses
  • Linear Hensel lifting
  • Quadratic Hensel lifting
  • Babai's Nearest Plane Algorithm
  • Matrix discrete logarithm
  • Matrix discrete logarithm (equation)
  • PartialInteger

Elliptic Curve Generation

  • Complex multiplication
  • Anomalous curves
  • MNT curves
  • Prescribed order
  • Prescribed trace
  • Supersingular curves

Small Roots

  • Polynomial roots using Groebner bases
  • Polynomial roots using resultants
  • Polynomial roots using Sage variety (triangular decomposition)
  • Aono method (Minkowski sum lattice) 39
  • Blomer-May method 41
  • Boneh-Durfee method 24
  • Coron method 42

Footnotes

  1. Galbraith D. S. et al., "Algorithms for the Approximate Common Divisor Problem" (Section 5) ↩

  2. Galbraith D. S. et al., "Algorithms for the Approximate Common Divisor Problem" (Section 4) ↩

  3. Galbraith D. S. et al., "Algorithms for the Approximate Common Divisor Problem" (Section 3) ↩

  4. Harasawa R. et al., "Comparing the MOV and FR Reductions in Elliptic Curve Cryptography" (Section 3) ↩

  5. Harasawa R. et al., "Comparing the MOV and FR Reductions in Elliptic Curve Cryptography" (Section 2) ↩

  6. Smart N. P., "The Discrete Logarithm Problem on Elliptic Curves of Trace One" ↩

  7. Hofman S. J., "The Discrete Logarithm Problem on Anomalous Elliptic Curves" ↩

  8. Heninger N., Shacham H., "Reconstructing RSA Private Keys from Random Key Bits" ↩

  9. Sedlacek V. et al., "I want to break square-free: The 4p - 1 factorization method and its RSA backdoor viability" ↩

  10. Ghafar AHA. et al., "A New LSB Attack on Special-Structured RSA Primes"

Download Tool
  • Known phi factorization 12
  • ROCA 13
  • Shor's algorithm (classical) 14
  • Twin primes factorization
  • Factorization of unbalanced moduli 15
  • 26
  • Extended Wiener's attack 27
  • Hastad's broadcast attack
  • Known CRT exponents attack 28
  • Partial known CRT exponents attack 29
  • Known private exponent attack
  • Low public exponent attack
  • LSB oracle (parity oracle) attack
  • Manger's attack 30
  • Nitaj's CRT-RSA attack 31
  • Non coprime public exponent attack 32
  • Partial key exposure 33 34 35
  • Related message attack
  • Stereotyped message attack
  • Wiener's attack
  • Wiener's attack for Common Prime RSA 36
  • Wiener's attack (Heuristic lattice variant) 37 38 39
  • Fast polynomial GCD using half GCD
  • Coron method (direct) 43
  • Ernst et al. methods 34
  • Herrmann-May method (unravelled linearization) 44
  • Herrmann-May method (modular multivariate) 45
  • Howgrave-Graham method 46
  • Jochemsz-May method (modular roots) 47
  • Jochemsz-May method (integer roots) 48
  • Nitaj-Fouotsa method 49
  • ↩
  • Nitaj A., Ariffin MRK., "Implicit factorization of unbalanced RSA moduli" ↩

  • Hinek M. J., Low M. K., Teske E., "On Some Attacks on Multi-prime RSA" (Section 3) ↩

  • Nemec M. et al., "The Return of Coppersmith’s Attack: Practical Factorization of Widely Used RSA Moduli" ↩

  • M. Johnston A., "Shor’s Algorithm and Factoring: Don’t Throw Away the Odd Orders" ↩

  • Brier E. et al., "Factoring Unbalanced Moduli with Known Bits" (Section 4) ↩

  • Joux A., "Authentication Failures in NIST version of GCM" ↩

  • Hlavac M., Rosa T., "Extended Hidden Number Problem and Its Cryptanalytic Applications" (Section 4) ↩

  • Coster M. J. et al., "Improved low-density subset sum algorithms" ↩

  • Contini S., Shparlinski I. E., "On Stern's Attack Against Secret Truncated Linear Congruential Generators" ↩

  • Frieze, A. et al., "Reconstructing Truncated Integer Variables Satisfying Linear Congruences" ↩

  • "The Learning with Errors Problem: Algorithms" (Section 1) ↩

  • R. Albrecht M. et al., "Prime and Prejudice: Primality Testing Under Adversarial Conditions" ↩

  • Bleichenbacher D., "Chosen Ciphertext Attacks Against Protocols Based on the RSA Encryption Standard PKCS #1" ↩

  • Boneh D., Durfee G., "Cryptanalysis of RSA with Private Key d Less than N^0.292" ↩ ↩2

  • Cherkaoui-Semmouni M. et al., "Cryptanalysis of RSA Variants with Primes Sharing Most Significant Bits" ↩

  • Coron J. et al., "Practical Cryptanalysis of ISO 9796-2 and EMV Signatures (Section 3)" ↩

  • Dujella A., "Continued fractions and RSA with small secret exponent" ↩

  • Campagna M., Sethi A., "Key Recovery Method for CRT Implementation of RSA" ↩

  • May A., Nowakowski J., Sarkar S., "Approximate Divisor Multiples - Factoring with Only a Third of the Secret CRT-Exponents" ↩

  • Manger J., "A Chosen Ciphertext Attack on RSA Optimal Asymmetric Encryption Padding (OAEP) as Standardized in PKCS #1 v2.0" ↩

  • Nitaj A., "A new attack on RSA and CRT-RSA" ↩

  • Shumow D., "Incorrectly Generated RSA Keys: How To Recover Lost Plaintexts" ↩

  • Boneh D., Durfee G., Frankel Y., "An Attack on RSA Given a Small Fraction of the Private Key Bits" ↩

  • Ernst M. et al., "Partial Key Exposure Attacks on RSA Up to Full Size Exponents" ↩ ↩2

  • Blomer J., May A., "New Partial Key Exposure Attacks on RSA" ↩

  • Jochemsz E., May A., "A Strategy for Finding Roots of Multivariate Polynomials with New Applications in Attacking RSA Variants" (Section 5) ↩

  • Nguyen P. Q., "Public-Key Cryptanalysis" ↩

  • Howgrave-Graham N., Seifert J., "Extending Wiener’s Attack in the Presence of Many Decrypting Exponents" ↩

  • Aono Y., "Minkowski sum based lattice construction for multivariate simultaneous Coppersmith's technique and applications to RSA" (Section 4) ↩ ↩2

  • Cao Z. et al., "Adleman-Manders-Miller Root Extraction Method Revisited" (Section 5) ↩

  • Blomer J., May A., "New Partial Key Exposure Attacks on RSA" (Section 6) ↩

  • Coron J., "Finding Small Roots of Bivariate Integer Polynomial Equations Revisited" ↩

  • Coron J., "Finding Small Roots of Bivariate Integer Polynomial Equations: a Direct Approach" ↩

  • Herrmann M., May A., "Maximizing Small Root Bounds by Linearization and Applications to Small Secret Exponent RSA" ↩

  • Herrmann M., May A., "Solving Linear Equations Modulo Divisors: On Factoring Given Any Bits" (Section 3 and 4) ↩

  • May A., "New RSA Vulnerabilities Using Lattice Reduction Methods" (Section 3.2) ↩

  • Jochemsz E., May A., "A Strategy for Finding Roots of Multivariate Polynomials with New Applications in Attacking RSA Variants" (Section 2.1) ↩

  • Jochemsz E., May A., "A Strategy for Finding Roots of Multivariate Polynomials with New Applications in Attacking RSA Variants" (Section 2.2) ↩

  • Nitaj A., Fouotsa E., "A New Attack on RSA and Demytko's Elliptic Curve Cryptosystem" ↩