offensive-crypto-attacks
Systematic methodology for identifying and exploiting cryptographic implementation weaknesses in real-world applications. Covers padding oracle attacks against CBC-mode ciphers with PKCS7 padding (Vaudenay's original attack through modern padbuster automation), ECB mode exploitation including block cut-and-paste and byte-at-a-time decryption, hash length extension attacks against SHA1/SHA256/MD5-based MACs using HashPump, RSA vulnerabilities including small public exponent, common modulus, Bleichenbacher PKCS1v1.5 padding oracle, and Coppersmith's method for partial key recovery. . Use when performing authorized red-team, pentest, or research work involving crypto attacks.
- Compatibility
- claude-code codex opencode
Pinned to revision 626b01ddea63, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/offensive-crypto-attacks/SKILL.md
- skills/offensive-crypto-attacks/LICENSE
- skills/offensive-crypto-attacks/README.md
- skills/offensive-crypto-attacks/agents/openai.yaml
Every link opens the file at its source, pinned to the revision this page describes.