Quantgnome Leap

  Challenge Progession:
Act II
Difficulty:
  Location:
Grand Hotel Lobby
Quantgnome Leap
Quantum Is Here

This challenge is all about preparing for "Post Quantum Computing". The idea that the current paradigm for cryptography cannot withstand the computing power of quantum computers isn't new. The Post Quantum Cryptography (PQC) methodologies are new though. These are methods of encrypting communication and data that are resistant to quantum computers. This isn't as much as a challenge as it is a walkthrough educational experience. As you progress in the challenge you will learn more and more about the different methods that are being developed for PQC.

Speak to Charlie in the Grand Hotel Lobby and he will give you more details.

Terminal MotD
First Leap

The terminal says to find and execute the PQC program on this sytem. We get dropped onto a box as user ggnome (ha). Looking around there is an SSH key pair in our home directory for user gnome1.

gnome1 SSH Public Key
We can likely just SSH to this system as gnome 1. Since we have the keypair here I can just issue the ssh command and login to this system:
ssh gnome1@127.0.0.1
First Leap
We learn here that the key we used to login with gnome1 is an RSA key. This encryption algorithm does not hold up in a post-quantum world. RSA can be solved with Shor's Algorithm.

Second Leap

The second leap to gnome2 will be similar. We just have to find a way to login as gnome2. I checked the .ssh directory and we have another key pair. This time it is an ED25519 key pair for gnome2. Lets ssh as gnome2 to this machine.

ED25519 Key Pair
ssh gnome2@127.0.0.1
Second Leap
The second leap is complete. The terminal informs us that the ED25519 key is also vulnerable to Shor's Algorithm. Ok on to the Third Leap with gnome3.

Third Leap

The third leap is to find a way to login to the gnome3 account. Again I looked in the .ssh directory and there is an SSH key pair. The public key does specify gnome3 as the user account. The key is so large that I used tail to print the last few hundred characters to see the user.

MAYO Key Pair
ssh gnome3@127.0.0.1

Third Leap
This time it is a "MAYO" encryption keypair. This key is much larger and is designed to be hardened against quantum computing attacks. You can check out the specification here:

https://csrc.nist.gov/csrc/media/Projects/pqc-dig-sig/documents/round-1/spec-files/mayo-spec-web.pdf

The terminal warns to use MAYO with caution because it is still a proof-of-concept and doesn't have a standardized implementation yet.

Fourth Leap

The final leap is to login with the gnome4 user account. Following the pattern I looked for ssh keys in the .ssh directory. Again I found an ssh key pair specifying gnome4 as the user account. I'm definitely not familiar with this algorithm though. Look at that filename!

Strange Key Pair
Like before, ssh to this machine as gnome4.
ssh gnome4@127.0.0.1

Fourth Leap
We learn that this is a hybrid approach, where 2 keys are generated: one classical key and one post-quantum key. Both keys must authenticate in order for login to succeed. This is a secure approach that according to NIST is atleast secure as AES128. Now on to the final leap!

Final Leap

This leap challenges us with logging in with the admin account. Keeping up with the pattern, I looked for ssh keys in .ssh...

Another Strange Key Pair
This key pair is for the admin user. So lets SSH again to this machine.
ssh admin@127.0.0.1

Success! We logged in with admin. This algorithm is another hybrid one. Read the details below to check it out.

Final Leap Success
This algorithm is security level 5, the highest. Now we just have to look around and find the final flag. I used the find command to look for files with the name "flag"..
Flag!
There it is. The flag text is "HHC{L3aping_0v3r_Quantum_Crypt0}". Enter this in your badge to complete this challenge!