An ongoing project working through the Cryptopals Crypto Challenges in Rust. The goal is to build low-level cryptographic primitives and attack implementations from scratch, developing a grounded understanding of how real-world cryptography works and breaks.
No high-level crypto libraries are used for the core challenge logic — only foundational encoding utilities (hex, base64) and Rust's standard library.
src/
├── main.rs
└── set_N/
├── mod.rs
└── ex_N.rs
Each set lives in its own module (set_1, set_2, ...) and each exercise in its own file. Auxiliary helpers shared across a set are kept in mod.rs.
Foundational encoding and XOR-based cryptanalysis.
| # | Title | Status |
|---|---|---|
| 1 | Convert hex to Base64 | ✅ Done |
| 2 | Fixed XOR | ✅ Done |
| 3 | Single-byte XOR cipher | 🔄 In progress |
| 4 | Detect single-character XOR | ⬜ Pending |
| 5 | Implement repeating-key XOR | ⬜ Pending |
| 6 | Break repeating-key XOR | ⬜ Pending |
| 7 | AES in ECB mode | ⬜ Pending |
| 8 | Detect AES in ECB mode | ⬜ Pending |
CBC mode, padding, and the first padding oracle.
| # | Title | Status |
|---|---|---|
| 9 | Implement PKCS#7 padding | ⬜ Pending |
| 10 | Implement CBC mode | ⬜ Pending |
| 11 | An ECB/CBC detection oracle | ⬜ Pending |
| 12 | Byte-at-a-time ECB decryption (Simple) | ⬜ Pending |
| 13 | ECB cut-and-paste | ⬜ Pending |
| 14 | Byte-at-a-time ECB decryption (Harder) | ⬜ Pending |
| 15 | PKCS#7 padding validation | ⬜ Pending |
| 16 | CBC bitflipping attacks | ⬜ Pending |
Breaking CBC and introducing stream ciphers.
| # | Title | Status |
|---|---|---|
| 17 | The CBC padding oracle | ⬜ Pending |
| 18 | Implement CTR, the stream cipher mode | ⬜ Pending |
| 19 | Break fixed-nonce CTR mode using substitutions | ⬜ Pending |
| 20 | Break fixed-nonce CTR statistically | ⬜ Pending |
| 21 | Implement the MT19937 Mersenne Twister RNG | ⬜ Pending |
| 22 | Crack an MT19937 seed | ⬜ Pending |
| 23 | Clone an MT19937 RNG from its output | ⬜ Pending |
| 24 | Create the MT19937 stream cipher and break it | ⬜ Pending |
SHA-1 and MD4 length extension, CTR bitflipping.
| # | Title | Status |
|---|---|---|
| 25 | Break "random access read/write" AES CTR | ⬜ Pending |
| 26 | CTR bitflipping | ⬜ Pending |
| 27 | Recover the key from CBC with IV=Key | ⬜ Pending |
| 28 | Implement a SHA-1 keyed MAC | ⬜ Pending |
| 29 | Break a SHA-1 keyed MAC using length extension | ⬜ Pending |
| 30 | Break an MD4 keyed MAC using length extension | ⬜ Pending |
| 31 | Implement and break HMAC-SHA1 with an artificial timing leak | ⬜ Pending |
| 32 | Break HMAC-SHA1 with a slightly less artificial timing leak | ⬜ Pending |
Public-key fundamentals, MITM, SRP.
| # | Title | Status |
|---|---|---|
| 33 | Implement Diffie-Hellman | ⬜ Pending |
| 34 | Implement a MITM key-fixing attack on Diffie-Hellman with parameter injection | ⬜ Pending |
| 35 | Implement DH with negotiated groups, and break with malicious g parameters | ⬜ Pending |
| 36 | Implement Secure Remote Password (SRP) | ⬜ Pending |
| 37 | Break SRP with a zero key | ⬜ Pending |
| 38 | Offline dictionary attack on simplified SRP | ⬜ Pending |
| 39 | Implement RSA | ⬜ Pending |
| 40 | Implement an E=3 RSA broadcast attack | ⬜ Pending |
Signature forgery, padding oracles on RSA.
| # | Title | Status |
|---|---|---|
| 41 | Implement unpadded message recovery oracle | ⬜ Pending |
| 42 | Bleichenbacher's e=3 RSA attack | ⬜ Pending |
| 43 | DSA key recovery from nonce | ⬜ Pending |
| 44 | DSA nonce recovery from repeated nonce | ⬜ Pending |
| 45 | DSA parameter tampering | ⬜ Pending |
| 46 | RSA parity oracle | ⬜ Pending |
| 47 | Bleichenbacher's PKCS 1.5 Padding Oracle (Simple) | ⬜ Pending |
| 48 | Bleichenbacher's PKCS 1.5 Padding Oracle (Complete) | ⬜ Pending |
Hash function internals and collision attacks.
| # | Title | Status |
|---|---|---|
| 49 | CBC-MAC message forgery | ⬜ Pending |
| 50 | Hashing with CBC-MAC | ⬜ Pending |
| 51 | Compression ratio side-channel attacks | ⬜ Pending |
| 52 | Iterated hash function multicollisions | ⬜ Pending |
| 53 | Kelsey and Schneier's expandable messages | ⬜ Pending |
| 54 | Kelsey and Kohno's nostradamus attack | ⬜ Pending |
| 55 | MD4 collisions | ⬜ Pending |
| 56 | RC4 single-byte biases | ⬜ Pending |
Elliptic curves, GCM, and advanced number theory attacks.
| # | Title | Status |
|---|---|---|
| 57 | Diffie-Hellman Revisited: Small Subgroup Confinement | ⬜ Pending |
| 58 | Pollard's Method for Catching Kangaroos | ⬜ Pending |
| 59 | Elliptic Curve Diffie-Hellman and Invalid-Curve Attacks | ⬜ Pending |
| 60 | Single-Coordinate Ladders and Insecure Twists | ⬜ Pending |
| 61 | Duplicate-Signature Key Selection in ECDSA (and RSA) | ⬜ Pending |
| 62 | Key-Recovery Attacks on ECDSA with Biased Nonces | ⬜ Pending |
| 63 | Key-Recovery Attacks on GCM with Repeated Nonces | ⬜ Pending |
| 64 | Key-Recovery Attacks on GCM with a Truncated MAC | ⬜ Pending |
- Rust systems programming: manual memory layout, ownership-driven API design, zero-copy byte manipulation
- Cryptographic fundamentals: block/stream ciphers, MACs, public-key systems, hash functions — implemented from scratch
- Adversarial thinking: every exercise is an attack, not a construction — breaking things to understand how they work
- Incremental design: a growing codebase with reusable primitives built up exercise by exercise
cargo runIndividual exercise entry points are exposed via set_N::ex_N::run() and called from main.rs.