Skip to content

Latest commit

 

History

History
55 lines (40 loc) · 5.9 KB

README.md

File metadata and controls

55 lines (40 loc) · 5.9 KB

RSA Common Modulus

A Python 3 script to describe the RSA Common Modulus Attack. Supports various output formats.

The RSA Common Modulus Attack can be explained in the following way. If a single plaintext has been encrypted to two ciphertexts by keys with the same modulus but different exponent, this plaintext can be recovered if gcd(e1, e2) = 1 and gcd(ct2, n)=1.

This is a script originally written by Andreas Pogiatzis in 2018 https://infosecwriteups.com/rsa-attacks-common-modulus-7bdb34f331a5

Maxim Masiutin ported this script in 2021 to Python 3 and added the option to configure the output format, and the code to check that the plaintexts from both decrypted messages to be the same.

This cript can be used as a CTF (capture the flag) tool.

Copyright 2018 Andreas Pogiatzis

Copyright 2021 Maxim Masiutin

References

  1. John M. Delaurentis, "A further weakness in the common modulus protocol for the RSA cryptoalgorithm", Cryptologia (1984), vol. 8, nr. 3, pag. 253-259, doi 10.1080/0161-118491859060, Taylor & Francis;
  2. Wen-Guey Tzeng "Common modulus and chosen-message attacks on public-key schemes with linear recurrence relations", Information Processing Letters (1999), Volume 70, Issue 3, Pages 153-156, ISSN 0020-0190;
  3. Hinek, M. and Charles C. Y. Lam. “Common modulus attacks on small private exponent RSA and some fast variants (in practice)." J. Math. Cryptol (2010).
  4. Andreas Pogiatzis "RSA Attacks: Common Modulus" https://infosecwriteups.com/rsa-attacks-common-modulus-7bdb34f331a5 InfoSec Write-ups (2018).

Usage

./rsa-common-modulus.py --help
usage: rsa-common-modulus.py [-h] -n MODULUS -e1 E1 -e2 E2 -ct1 CT1 -ct2 CT2 [-q] [-of {decimal,hex,base64,quoted,ascii,utf-8,raw}]

RSA Common modulus attack

optional arguments:
  -h, --help            show this help message and exit
  -q, --quiet
  -of {decimal,hex,base64,quoted,ascii,utf-8,raw}, --outputformat {decimal,hex,base64,quoted,ascii,utf-8,raw}

required named arguments:
  -n MODULUS, --modulus MODULUS
                        Common modulus
  -e1 E1, --e1 E1       First exponent
  -e2 E2, --e2 E2       Second exponent
  -ct1 CT1, --ct1 CT1   First ciphertext
  -ct2 CT2, --ct2 CT2   Second ciphertext

Example

./rsa-common-modulus.py --moduluse1 3 --cte2 65537 --ctoutputformat ascii --quiet