# RsaCtfTool: Automated RSA Attack Tool for CTF Challenges

> RsaCtfTool is a Python tool that automates attacks on weak RSA public keys, covering Wiener's attack, Boneh-Durfee, Fermat factorization, Pollard Rho, ECM, and dozens of other methods. It is primarily intended for educational purposes and Capture the Flag competitions, where RSA challenges use intentionally weak key parameters.

**RsaCtfTool/RsaCtfTool** — RSA attack tool (mainly for ctf) - retrieve private key from weak public key and/or uncipher data

- Repository: https://github.com/RsaCtfTool/RsaCtfTool
- Stars: 7,160 · Forks: 1,004
- Language: Python
- License: MIT
- Published: 2026-09-22 · Updated: 2026-09-22 · Language: en
- Canonical page: https://hysenlabs.com/projects/rsactftool-rsactftool

## What RSA Weaknesses RsaCtfTool Targets and Who Uses It

RSA security depends on the difficulty of factoring the modulus n into its two prime factors p and q. A properly generated RSA key uses large primes chosen randomly, making factorization computationally infeasible. CTF challenge designers, however, deliberately weaken key generation to create solvable puzzles. They use primes that are too close together, exponents that are too small, keys that share factors, or primes with special structure that algorithms like Wiener's attack can exploit.

RsaCtfTool automates the process of trying these attacks in sequence. A CTF competitor who receives a public key file and ciphertext can run the tool against the key and have it attempt all applicable attack methods automatically, rather than manually identifying which mathematical weakness applies and implementing the attack from scratch.

The README is explicit that the tool is primarily intended for educational purposes. The disclaimer that not every key can be broken in a reasonable timeframe is part of the overview. The project also restricts scope: it only supports RSA textbook semiprime composite modulus, meaning n = p * q where p and q are prime. Keys with more than two prime factors (multiprime RSA) are not supported.

## Installing RsaCtfTool in a Virtual Environment or Docker

The README recommends a Python virtual environment as the standard installation path. Python 3.9 or later is required:

```bash
python3 -m venv venv
source venv/bin/activate
pip install -e .
```

The tool can also run in Docker, which avoids Python dependency conflicts:

```bash
docker build -t rsactftool/rsactftool .
docker run -it --rm -v $PWD:/data rsactftool/rsactftool <arguments>
```

The Docker image is built from python:3-alpine and installs GMP, MPFR, MPC, OpenSSL, and libffi for the mathematical dependencies. The requirements.txt lists cryptography, gmpy2, pycryptodome, z3-solver, tqdm, requests, and factordb-pycli as core dependencies.

SageMath is listed as optional but recommended. The README notes it is not pip-installable and must be installed separately from sagemath.org. Several of the more advanced factorization routines in the sage/ subdirectory use SageMath's polynomial and lattice reduction capabilities. The wolframalpha integration is also optional and listed in pyproject.toml under optional-requirements.

## Basic Usage: Recovering a Private Key and Decrypting Files

The three core operations are private key recovery, file decryption, and targeted attack selection. The README gives these as the primary examples:

```bash
RsaCtfTool --publickey key.pub --private
```

This attempts all applicable attacks on key.pub and prints the recovered private key if one succeeds:

```bash
RsaCtfTool --publickey key.pub --decryptfile ciphertext
```

This recovers the key and uses it to decrypt the ciphertext file. To run a single named attack rather than all of them:

```bash
RsaCtfTool --publickey key.pub --attack wiener --private
```

Additional utility commands let a competitor reconstruct a public key from known n and e values, dump key parameters, check for the ROCA vulnerability across multiple keys, send discovered prime factors to factordb, and convert SSH public keys to PEM format:

```bash
RsaCtfTool --dumpkey --key key.pub
RsaCtfTool --isroca --publickey "examples/*.pub"
RsaCtfTool --publickey "*.pub" --private --sendtofdb
```

For more options, RsaCtfTool --help lists all flags. Running pytest tests/ --collect-only shows the available test cases, which also serve as a catalogue of supported attack scenarios.

## Non-Factorization Attacks: When Factoring Is Not the Weak Link

Several RSA attacks do not attempt to factor n at all. They exploit structural weaknesses in the exponents or in how a key is used.

Wiener's attack applies when the private exponent d is too small relative to n. Specifically, it works when d is less than n to the power of 0.25, by using continued fraction expansion of e/n to recover d. Hastad's broadcast attack exploits a small public exponent e (commonly 3) used to encrypt the same message to multiple recipients without padding. Boneh-Durfee extends the Wiener bound using lattice reduction, recovering d when d is less than n to the power of 0.292.

The small CRT exponent attack targets implementations that use the Chinese Remainder Theorem with small exponents. The same-n-huge-e attack applies when the same modulus is used with an unusually large public exponent. Partial q and partial d attacks work when the attacker knows portions of the key parameters.

## Factorization Methods and CTF-Specific Techniques

The factorization attack table in the README lists methods covering a range of mathematical structures. Fermat's factorization method works when p and q are close together; this is one of the most common CTF weaknesses. Pollard Rho is a general-purpose factorization algorithm. ECM (Lenstra Elliptic Curve Factorization) is effective when one prime factor is smooth (composed of small prime factors). Pollard p-1 and Williams p+1 similarly target smooth prime factors.

The ROCA vulnerability targets a specific flaw in the Infineon key generation algorithm that was disclosed in 2017. SQUFOF uses Shanks's square forms factorization. Quadratic Sieve and Dixon's method are general-purpose algorithms for larger numbers. The Factordb integration queries factordb.com's database of known factorizations.

CTF-specific methods include Noveltyprimes, Past CTF Primes (a database of prime numbers that have appeared in previous competitions), Gimmicky Primes, and Non-RSA forms where n follows a pattern like b to the power of x. The Z3 Theorem Prover integration applies constraint solving to recover key parameters when other methods fail.

## Hard Limits: What RsaCtfTool Cannot Break

The README states two hard limits explicitly. First, the tool only supports RSA with a semiprime modulus (n = p * q). Keys with three or more prime factors (multiprime RSA) are not in scope. Second, not every key can be broken in a reasonable timeframe: the tool automates known attacks on known weaknesses, and a key without any detectable weakness will exhaust all methods without a result.

For factorizations beyond what the built-in methods can handle, the README itself points to msieve, yafu, and cado-nfs as tools designed for general-purpose large integer factorization. These are separate projects that require significantly more setup and computational resources.

The ECM-specific --ecmdigits flag controls how large a factor ECM will attempt to find, with a higher digit count taking longer. For keys where ECM might succeed with more effort, this flag lets the operator trade time for coverage:

```bash
RsaCtfTool --publickey key.pub --ecmdigits 25 --private
```

## RsaCtfTool vs Manual SageMath and License Notes

The manual alternative to RsaCtfTool is using SageMath directly. SageMath is a comprehensive mathematics software system with built-in number theory and factorization functions. A CTF competitor who knows exactly which attack applies, such as Wiener or Coppersmith lattice reduction, can implement it in a SageMath notebook with full control over parameters.

RsaCtfTool's advantage over manual SageMath work is breadth: it tries dozens of attacks automatically without the competitor needing to identify the weakness first. Its disadvantage is that when no built-in attack matches, the competitor is back to manual implementation anyway. RsaCtfTool also uses SageMath as an optional backend for its own most complex routines, so the two are complementary rather than mutually exclusive.

The repository was originally released under GPLv3. The README notes it has been relicensed under MIT. The last push was on 2026-09-25. The test suite uses pytest with markers for slow, network-dependent, and attack integration tests. The --attack flag value wiener maps to an attack integration test in test_attacks.py, providing a direct path to verifying a specific method works in the installed environment.

## Conclusion

RsaCtfTool is the right tool for CTF competitors and security students who encounter RSA challenges with intentionally weak key generation. It is the wrong tool for testing production RSA keys: the README states that not every key can be broken in a reasonable timeframe, and real-world 2048-bit RSA keys generated with a proper random number generator are not in scope for any of these attacks. The only supported modulus type is textbook semiprime composite, so multiprime RSA is out of scope. The repository carries an MIT license (relicensed from the original GPLv3), and the last push was on 2026-09-25.

## FAQ

### How do I use RsaCtfTool?

The basic command is RsaCtfTool --publickey key.pub --private to attempt to recover the private key, or RsaCtfTool --publickey key.pub --decryptfile ciphertext to decrypt a file. Run RsaCtfTool --help for a full list of options, or specify a single attack with --attack wiener (or another attack name).

### What RSA attacks does RsaCtfTool support?

The README lists Wiener's attack, Hastad's broadcast attack, Boneh-Durfee, small CRT exponent, lattice reduction, Fermat factorization, Pollard Rho, ECM, Pollard p-1, Williams p+1, ROCA, SQUFOF, Quadratic Sieve, Factordb lookup, common factor attacks, and CTF-specific methods including Past CTF Primes and Z3 Theorem Prover.

### Does RsaCtfTool work on production RSA keys?

The README states the tool is primarily for educational purposes and that not every key can be broken in a reasonable timeframe. It targets intentionally weak CTF key parameters. The tool also only supports textbook semiprime RSA (n = p * q), not multiprime moduli.

## Sources

- [Issues](https://github.com/RsaCtfTool/RsaCtfTool/issues)
- [License: MIT](https://github.com/RsaCtfTool/RsaCtfTool/blob/master/LICENSE)
- [README](https://github.com/RsaCtfTool/RsaCtfTool/blob/master/README.md)
- [RsaCtfTool/RsaCtfTool on GitHub](https://github.com/RsaCtfTool/RsaCtfTool)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/rsactftool-rsactftool
