Cryptography CTF Challenges
Classical, symmetric, asymmetric & PGP challenges.
Round duration
12 hours
Format
Jeopardy-style CTF
Team size
1–3 members
Cryptography challenges rarely require you to invent a new attack. They require you to notice that a system is using a construction it should not be, and then apply a known weakness to it. The skill being tested is recognising which guarantee a cipher is actually providing — and which one it is quietly not.
The category spans the full range of practical crypto: classical ciphers where the weakness is in the algorithm, modern symmetric and asymmetric schemes where the weakness is in the implementation or the parameters, and public-key infrastructure tasks where the weakness is in how keys and signatures are handled. You will be expected to write code to solve these — Python with `pycryptodome` or `sympy` covers almost everything you will meet.
What makes this category rewarding is that the reasoning is fully self-contained. There is no environment to explore and no traffic to capture. You have the ciphertext, the algorithm, and enough time to work it out — and the moment you spot the flaw, the solve is usually twenty lines of code.
What you’ll actually face
Challenge types modelled on the work real security teams do, weighted toward the mid and upper difficulty bands.
Classical ciphers
Vigenère, substitution and transposition ciphers broken by frequency analysis, Kasiski examination or crib dragging rather than by brute force.
RSA and public-key
Shared primes, small exponents, textbook padding, faulty signature checks and key-recovery attacks where the modulus leaks through timing or randomness.
Symmetric ciphers
AES in ECB mode, reused nonces, short keys and known-plaintext attacks against block ciphers used outside the way they were designed for.
Hashing & password security
Weak hash functions, unsalted digests, length-extension attacks and password hashes that can be attacked faster than brute force.
PGP & key handling
Key generation with poor entropy, messages encrypted to the wrong key, detached signatures that can be stripped or replayed.
Encoding traps
Base64, hex and custom encodings that look like security but provide none, layered over a real cipher that does the actual work.
Tools you’ll reach for
- Python + pycryptodome
- SymPy
- SageMath
- hashcat / John the Ripper
- GnuPG
- CyberChef
- RsaCtfTool
- z3 solver
How to prepare
None of this is required to enter — it is simply the shortest path to scoring points in this discipline.
Actually implement AES, RSA and a Vigenère cipher from scratch in Python. Writing them is what makes recognising their misuse automatic.
Learn to factor small integers quickly and to read `n`, `e`, `c` triples without hesitation — you will be doing it under a clock.
Understand padding: PKCS#7, OAEP and ECB-vs-CBC. Most symmetric challenge solves are a padding or mode mistake in disguise.
Practise reading `sympy` output and using `discrete_log` when a challenge hands you a small group.
Keep a scratch file of the ten solves you have done before. Crypto is the one category where muscle memory pays off most.
Quick facts
Everything about Ghost Protocol CTF 2.0 at a glance.
- Online qualifier
- 17 October 2026 · 12 hours · remote
- Grand finale
- 24 October 2026 · 12 hours · on-ground
- Format
- Jeopardy-style CTF
- Team size
- 1–3 members (solo entry allowed)
- Registration fee
- Free per team
- Prize pool
- Up to ₹51,000
- Challenge categories
- 10 disciplines
- Eligibility
- Any student in an undergraduate or postgraduate programme, any stream
- Venue
- NIET Greater Noida
- Organised by
- Cyber Invaders · NIET Greater Noida
Adjacent disciplines
Competitors in CTF teams tend to specialise — here is where the skills overlap.
Ready to prove it on the scoreboard?
Cryptography is one of 10 disciplines in Ghost Protocol CTF 2.0. Entry is free and teams of 1–3 are welcome.