Cryptography
Cryptography is the mathematics of secure communication. CTF crypto challenges teach you how ciphers work by making you break weak ones. You'll start with classical pen-and-paper ciphers, move through modern encoding schemes and hash functions, and eventually attack real-world protocols like RSA when they're implemented incorrectly.
Guides for this path
Read these alongside the challenges below. The first one orients you; the rest go deeper on the techniques each step needs.
- The picoCTF Cryptography Roadmap: From Caesar to Elliptic CurvesCryptography roadmap for CTF: a tiered path from encodings and classical ciphers through RSA, AES, Diffie-Hellman, and elliptic curves, with practice picks.
- Classical Ciphers for CTF: Caesar, Vigenère, and SubstitutionClassical ciphers for CTF: the four tells that name a Caesar, Vigenere, or substitution cipher on sight, so you can stop guessing and break it in one click.
- Base64, Hex, and Common CTF Encodings ExplainedCTF encodings decoded: identify and crack Base64, hex, binary, octal, ROT13, URL encoding, Morse, and more, with a copy-paste one-liner for each format.
- Hash Cracking for CTF: MD5, SHA-1, SHA-256 and Beyond (picoCTF 2026)Hash cracking for CTF: identify hash types, run hashcat and John the Ripper, use rainbow tables and online lookups, and solve picoCTF 2026 and 2025 hash challenges.
- Reversing Custom Ciphers for CTF: Breaking Homebrew EncryptionBreak homebrew CTF encryption with a three-probe chosen-plaintext test: classify the cipher as byte-independent, arithmetic, or stateful, then invert it.
- RSA Attacks for CTF CryptographyRSA attacks for CTF: small public exponent, weak modulus factoring, common modulus, Wiener's attack, and oracle decryption, with picoCTF challenge links.
- Step 01
Classical Ciphers
Before modern cryptography there were substitution and transposition ciphers. A Caesar cipher shifts each letter by a fixed amount; a Vigenere cipher uses a repeating key. These are trivially broken with frequency analysis, but understanding them builds the intuition you need to attack anything harder.
- Step 02
Encoding and Hashing
Encoding (Base64, hex, URL encoding) is not encryption but it looks like it. Hash functions (MD5, SHA-1, bcrypt) are one-way transforms used to store passwords. You'll learn the difference between the two and practice cracking hash digests using wordlists and rainbow tables.
- Step 03
Custom Encryption Schemes
Rolling your own crypto is almost always a mistake. These challenges present home-grown encryption implementations with subtle flaws: simple XOR with a short key, Caesar-based schemes, and alphabet remapping. The skill is reading the code, understanding the transform, and inverting it.
- Step 04
RSA and Public-Key Cryptography
RSA is the most widely deployed public-key cryptosystem. When properly used it's secure, but small primes, reused parameters, and padding oracle attacks make weak RSA implementations breakable with basic number theory. These challenges introduce the math and show where real-world RSA goes wrong.