Very Smooth


Forget safe primes... Here, we like to live life dangerously... >:)


  1. 1.
    Searching online for "pollard smooth prime" finds Pollard's p − 1 algorithm.
  2. 2.
    Using RsaCtfTool with the pollard_p_1 attack by running python --uncipher [c] -e 65537 -n [n] --attack pollard_p_1 doesn't work since it doesn't try enough primes (relevant source code). So, we adapt their script to create the solution, which tries 7000 primes.
  3. 3.
    Interestingly, this prime is in factordb so RsaCtfTool will print the flag immediately when using the factordb attack.