Curveware — HackTheBox Challenge Writeup
Challenge Overview
Curveware is a hard Cryptography / Reverse Engineering challenge simulating a ransomware infection. We are given a 64-bit Windows executable (curveware.exe) and a directory of encrypted files appended with .vlny[10-hex].
Our objective is to reverse-engineer the cryptographic scheme, exploit partial nonce leakage via lattice reduction, and decrypt flag.txt.
Binary Analysis & File Structure
Static analysis with Ghidra reveals:
- ▹Crypto Engine: Statically linked against libecc (ANSSI's Elliptic Curve library) using NIST P-256 (
secp256r1). - ▹Key Generation: Uses
CryptGenRandomto generate a single 32-byte secret key $d$, serving as both the AES-256-CBC key and the ECDSA private key. - ▹Nonce Leakage: The 10-character hex extension suffix (e.g.,
.vlny0742e9337a) exposes the lower 40 bits of the ephemeral nonce (k = SHA256(plaintext)).
::Encrypted File Layout
| Component | Offset / Range | Size | Description |
|---|---|---|---|
| Signature $r$ | 0x00 – 0x1F | 32 Bytes | ECDSA signature component $r$ |
| Signature $s$ | 0x20 – 0x3F | 32 Bytes | ECDSA signature component $s$ |
| AES IV | 0x40 – 0x4F | 16 Bytes | AES-256-CBC Initialization Vector |
| AES Ciphertext | 0x50 – EOF | Variable | Encrypted file payload |
To decrypt any file, strip the first 64 bytes (signature) and next 16 bytes (IV), then decrypt the payload using AES-256-CBC with the key $d$.
Cryptographic Vulnerability: Hidden Number Problem (HNP)
The binary computes signatures as:
Since the lower 40 bits of k are exposed in the filename extension (leak), we express k as:
::Deriving the HNP Relation
Substituting k into the signature equation:
- ▹
Substitute
k:~ / textleak + 2⁴⁰ · x ≡ r + s·d (mod n) - ▹
Rearrange & multiply by
(2⁴⁰)⁻¹ (mod n):~ / textx - (2⁴⁰)⁻¹ · s·d + (2⁴⁰)⁻¹ · (leak - r) ≡ 0 (mod n)
With 18 encrypted sample files, we construct an $(m+2) \times (m+2)$ lattice matrix and apply LLL reduction to recover the secret key $d$.
Exploitation & Key Recovery
::1. Lattice Reduction (solve.sage)
Note: SageMath is not available on Ubuntu 22.04 LTS. You can install it by adding the EPEL repository to your APT sources.
Recovered Private Key: 0xc5120eda0305ce74a125b5bd727e4fee5a24457ab376b69578c179f8440881e0
::2. Decryption & Flag Capture (solve.py)
References
- ▹Hidden Number Problem (HNP): D. Boneh and R. Venkatesan, "Hardness of Computing the Most Significant Bits of Secret Keys in Diffie-Hellman and Related Schemes", CRYPTO '96.
- ▹ECDSA Nonce Attacks: N. Smart, "The Exact Security of ECDSA of Small Nonces", 2001.
- ▹libecc Library: ANSSI Open Source Elliptic Curve Cryptography Library — GitHub Repository.
- ▹SageMath LLL Reduction: SageMath Documentation on Integer Lattices and LLL Reduction.

Red Team Consultant · Penetration Tester · Bug Bounty Hunter
Offensive security professional with 250+ vulnerabilities reported across 50+ organizations including Atlassian, Vimeo, and AT&T. Sharing research, tools, and field notes.