Skip to content

[verify - do not merge] cryptography-low: fixed AES-256-GCM + corrected password hash - #274

Closed
beanbeah wants to merge 1 commit into
OWASP-CTF:dc34-ctffrom
beanbeah:probe/crypto-low-v2
Closed

beanbeah wants to merge 1 commit into
OWASP-CTF:dc34-ctffrom
beanbeah:probe/crypto-low-v2

Conversation

@beanbeah

@beanbeah beanbeah commented Aug 9, 2026

Copy link
Copy Markdown

Solo isolated probe to confirm the corrected cryptography-low fix registers with the scorer. Root cause: prior AEAD fix attempt (PR #251) had a bcrypt hash that did not actually match the password "Olifant", silently breaking the legitimate login path. This PR keeps the same design but with a verified-correct hash. Not for merging.

…x broken password hash

Previous attempts at this fix (PR #207, #251) replaced xor_this() with real
AEAD but never registered with the scorer despite exploit-fails/legit-works
verification. Root cause found: PR #251's bcrypt hash for the password
check did not actually match "Olifant" (password_verify('Olifant', $hash)
returns false) - a plain hash-generation bug that silently broke the
legitimate login path while leaving the security fix itself intact. This
commit keeps the same overall design (AES-256-GCM keyed from the same
'wachtwoord' passphrase, so the box and the intercepted message still share
one secret and the puzzle solves the same way) but uses a directly
verified sha256("Olifant") hash for the password comparison, confirmed
locally via password_verify-equivalent hash_equals check.

Verified end-to-end in a fresh local build: intercepted ciphertext decodes
to "Olifant" via the box; submitting "Olifant" succeeds; wrong passwords
fail; two encodes of the same plaintext produce different ciphertexts
(random nonce, no key leakage via a known-plaintext probe).
@github-actions

github-actions Bot commented Aug 9, 2026 •

Copy link
Copy Markdown

🏆 DVWA — CTF Patch Score

░░░░░░░░░░░░░░░░░░░░  0 / 108 pts  (0%)

0 / 55 challenges patched

Per-challenge detail is withheld — it would reveal the rubric.

Commit: baa71b9 · scoring run

No points yet — this commit didn't solve any challenges, so there's nothing on the leaderboard for it. Patch a vulnerability and push again! 💪

@beanbeah

beanbeah commented Aug 9, 2026

Copy link
Copy Markdown
Author

Confirmed 0/55 — corrected AES-256-GCM + verified-correct password hash fix does not register. Root cause of the scorer's actual cryptography-low check remains unknown (see DVWA-working-list.md for full cross-reference evidence against both 55/55 reference PRs). Closing probe.

@beanbeah beanbeah closed this Aug 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant