Talk With an Expert

Learning CBC Bit-flipping Through Gamification

Learning CBC Bit-flipping Through Gamification (PDF, 4.92MB)Published: 24 Apr, 2018
Created by:
Jeremy Druin

Cryptanalysis concepts like CBC Bit-flipping can be difficult to grasp through study alone. Working through hands-on exercises is a common teaching technique intended to assist, but freely available training tools may not be readily available for advanced web application penetration testing practice. To this end, this paper will describe CBC bit-flipping and offer instruction on trying this cryptanalysis technique. Also, a CBC bit-flipping game will be provided within the OWASP Mutillidae II web application. Mutillidae is a large collection of deliberately vulnerable web application challenges designed to teach web security in a stand-alone, local environment.