Symmetric vs asymmetric
Understanding the difference between symmetric and asymmetric encryption —and above all the modes of operation— is the basis for exploiting most real-world crypto flaws. The theory is simple; what’s exploitable lives in the usage details.
Symmetric vs asymmetric
Section titled “Symmetric vs asymmetric”SYMMETRIC (AES, ChaCha20) same key to encrypt and decrypt; fast; for large volumes of data problem: how do the two parties share the key?
ASYMMETRIC (RSA, ECC) key pair: public (encrypt/verify) + private (decrypt/sign); slow solves key distribution and enables digital signatures
HYBRID (the real world: TLS, PGP, Signal) asymmetric to exchange a session key -> symmetric for the dataModes of operation (where AES breaks)
Section titled “Modes of operation (where AES breaks)”AES encrypts 128-bit blocks. The mode says how blocks are chained, and that’s where flaws live:
ECB each block independent -> equal plaintext blocks = equal ciphertext pattern LEAK (the "ECB penguin"); lets you cut/paste blocks. NEVER use.CBC chains with XOR of the previous block; needs a random IV malleable without a MAC (bit-flipping); vulnerable to padding oracle (crypto-padding)CTR turns AES into a stream cipher (keystream XOR plaintext) reusing (key,nonce) = CATASTROPHE: XOR of two texts reveals bothGCM CTR + authentication (AEAD) -> confidentiality + integrity. RECOMMENDED UNIQUE nonce per key: repeating the nonce breaks authentication (forgery)Classic attacks (lab)
Section titled “Classic attacks (lab)”Detecting and exploiting ECB
Section titled “Detecting and exploiting ECB”# encryption oracle: send repeated blocks and see repeated ciphertextAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAA -> two IDENTICAL encrypted blocks = ECB# "ECB byte-at-a-time": if the server encrypts INPUT‖SECRET in ECB,# you recover the secret byte by byte by aligning blocks (classic cryptopals challenge)Keystream reuse (CTR/stream with repeated nonce)
Section titled “Keystream reuse (CTR/stream with repeated nonce)”C1 = P1 XOR KS C2 = P2 XOR KS (same nonce -> same KS)C1 XOR C2 = P1 XOR P2 -> "crib dragging" recovers both texts without the keyMalleability / bit-flipping (CBC without MAC)
Section titled “Malleability / bit-flipping (CBC without MAC)”# flipping a byte in the CBC IV/ciphertext block changes, in a controlled way,# the decrypted plaintext of the next block -> e.g. flip "role=user" to "role=admin"- PyCryptodome to build oracles and attacks; CyberChef to prototype.
- openssl enc to encrypt/decrypt and reproduce modes; the cryptopals sets to practice.
Defense
Section titled “Defense”- AEAD by default: AES-GCM or ChaCha20-Poly1305; never raw CBC/CTR without a MAC.
- Unique nonce per key (counter or random 96-bit in GCM); random IV in CBC.
- Ban ECB. Encrypt-then-MAC if not using AEAD. Key rotation and management with KMS/HSM.
CVEs and real-world cases
Section titled “CVEs and real-world cases”- ECB in cookies/tokens: structure leak and block cut-paste, recurring in web audits.
- Nonce reuse in GCM: authentication break; documented in misconfigured TLS and VPN implementations.
- Zerologon (CVE-2020-1472) stems from incorrect use of AES-CFB8 with a fixed IV in Netlogon.
Testing checklist
Section titled “Testing checklist”- Identify algorithm and mode (block size 16 → AES)
- ECB test: repeated blocks → repeated ciphertext
- ECB byte-at-a-time if there’s an INPUT‖SECRET oracle
- CTR/stream: look for nonce reuse (XOR of texts)
- CBC without MAC: try bit-flipping and padding oracle (Padding oracle)
- GCM: is the nonce repeated? → tag forgery
- Verify the defense uses AEAD and a unique nonce