Cryptography is the foundation of information security. This module covers encryption algorithms (symmetric, asymmetric, hash), public key infrastructure (PKI), digital signatures, key management, cryptographic attacks, secure communication protocols, and wireless cryptography. Understanding these concepts is essential for ethical hackers to evaluate security postures and identify weaknesses.
The CEHStudy app carries 17 flashcards for Module 20 across 3 sections — sort every stem by mechanism first: symmetric (same key both ways, e.g. AES), asymmetric (public/private key pairs, e.g. RSA and ECC), one-way hash (fixed-size digest, e.g. SHA-256) — with signatures, HMAC, and PKI layered on top. That sorting is what most Module 20 questions actually test.
Digital signatures: DSS, PKCS standards, ECDSA, signature process
Public Key Infrastructure (PKI): CAs, RAs, X.509 certificates, CRL, OCSP
Key management: distribution methods, lifecycle, HSM, key rotation
Cryptographic attacks: brute force, known/chosen plaintext, side channel, collision
Secure protocols: TLS/SSL, IPsec, SSH, PGP/GPG
Wireless cryptography: WEP, WPA, WPA2, WPA3
Important Terms & Concepts
Symmetric Encryption: Uses the same key for encryption and decryption. Fast and efficient for bulk data. Examples: AES (128/192/256-bit), DES (56-bit, broken), 3DES, Blowfish, ChaCha20. Modes of operation: ECB, CBC, CFB, OFB, GCM.
Asymmetric Encryption: Uses a public/private key pair. Public key encrypts, private key decrypts. Slower than symmetric but solves key distribution. Examples: RSA (2048-4096-bit), ECC (256-521-bit), DSA (signatures only), Diffie-Hellman (key exchange).
Memorize the difference between symmetric and asymmetric encryption with specific algorithm examples
Know hash function strengths/weaknesses — which are broken (MD5, SHA-1) vs secure (SHA-256+, BLAKE2)
Understand the digital signature process step-by-step
Learn PKI components and how CAs, RAs, and certificates work together
Know minimum key size requirements for each algorithm type
Understand how secure protocols (TLS, IPsec, SSH) combine symmetric and asymmetric crypto
Frequently Asked Questions
Why is cryptography critical for ethical hackers? Cryptography is the backbone of security. Ethical hackers must understand it to evaluate encryption strength, identify weak algorithms (DES, MD5), assess PKI configurations, and test protocol implementations for vulnerabilities.
What's the most important algorithm to know for the exam? AES — it's the current symmetric standard. Also know RSA for asymmetric, SHA-256 for hashing, and the difference between WPA2 (AES) and WPA3 (forward secrecy).
How does PKI relate to digital certificates? PKI is the entire framework that issues, manages, and revokes digital certificates. The CA signs certificates, RA verifies identities, and CRL/OCSP handle revocation. Certificates bind public keys to real-world identities.
Cryptography (Module 20) is arguably the most foundational domain on the Certified Ethical Hacker v13 (CEH v13) exam — it underpins virtually every other security control. You won't implement algorithms from scratch, but you must identify which algorithm is in use, evaluate its strength against current attacks, recognize broken or deprecated designs, and understand how protocols combine symmetric and asymmetric techniques. Cryptography appears explicitly in Module 20 (approximately 8% of the exam) and implicitly throughout other domains — password hashing (Modules 5-7), wireless security (Module 16), protocol security (Modules 12-13), digital signatures and certificates (throughout). Approximately 10-12 questions directly test cryptographic knowledge.
Key Concepts in Cryptography
Symmetric Encryption & AES: Symmetric ciphers use one key for both encryption and decryption. The exam's current standard is AES (Advanced Encryption Standard): AES-128, AES-192, AES-256 with 128-bit block size. Critical distinctions: (1) ECB mode is insecure for most uses — identical plaintext blocks produce identical ciphertext blocks and reveal patterns (the "ECB penguin" example); (2) CBC adds an IV (Initialization Vector) for randomness but requires padding and is vulnerable to padding oracle attacks; (3) GCM (Galois/Counter Mode) provides confidentiality AND integrity (authenticated encryption) in one operation — TLS 1.3's default. Deprecated algorithms also tested: DES (56-bit key, brute-force broken since 1999), RC4 (keystream biases discovered; used in WEP and early TLS), 3DES (phased out over its 64-bit block size — Sweet32 birthday attack). Exam cues: "bulk data encryption" → almost always AES; "deprecated but still found in legacy systems" → think RC4 or DES.
Asymmetric Encryption & Key Exchange: Asymmetric algorithms use mathematically related key pairs. Must-know: (1) RSA — most widely deployed; used for encryption (RSA-OAEP padding) and signatures (RSA-PSS or PKCS#1 v1.5); minimum 2048-bit keys recommended (NIST SP 800-57), 3072-bit for long-term security through 2030; (2) ECC (Elliptic Curve Cryptography) — equivalent security with much smaller keys: P-256 ≈ RSA-3072, P-384 ≈ RSA-7680; critical for IoT/mobile where key size matters; (3) Diffie-Hellman (DH) — key agreement, not encryption: two parties derive a shared secret without transmitting it; ECDHE is the modern variant providing forward secrecy in TLS; (4) DSA (Digital Signature Algorithm) — signature-only (cannot encrypt); ECDSA is its elliptic-curve equivalent. Frequently tested: "Which algorithm provides forward secrecy?" — ECDHE/DHE, not RSA: RSA key exchange uses the server's long-term private key, so a compromised key decrypts all past sessions. Forward secrecy means each session's keys are derived fresh and can't be retroactively decrypted.
Cryptographic Hash Functions: Hash functions produce a fixed-size digest from variable-length input. Properties the exam tests: (1) deterministic — same input always gives the same output; (2) pre-image resistance — given hash H, no feasible M with hash(M)=H; (3) collision resistance — can't find M1≠M2 with hash(M1)=hash(M2); (4) avalanche effect — a 1-bit input change flips ~50% of output bits. Secure: SHA-256 (256-bit), SHA-384, SHA-512, SHA-3 (Keccak-based), BLAKE2, BLAKE3. Broken/deprecated: MD5 (practical collision attacks since 2004 — MD Collide tool), SHA-1 (SHAttered proof-of-concept 2017; NIST deprecated it for digital signatures in 2013). Both are STILL found in legacy systems and exploitable: MD5 collisions can forge code signing certificates, and SHA-1 collisions have been demonstrated in certificate forgery — any system still accepting SHA-1 signatures is vulnerable to a chosen-prefix collision attack where a malicious certificate matches a legitimate one's hash.
Digital Signatures & PKI: Digital signatures provide three properties at once: authentication (proves who signed), integrity (any modification invalidates the signature), and non-repudiation (signer cannot deny having signed). Signing: Hash(message) → Encrypt(hash, sender's PRIVATE key) → append signature. Verification: Decrypt(signature, sender's PUBLIC key) → Hash(received message) → compare. PKI components tested: (1) CA (Certificate Authority) — signs certificates, holds the root key; (2) RA (Registration Authority) — verifies identity before the CA issues; (3) X.509 certificate format — public key, subject/issuer DNs, validity period, serial number, signature algorithm; (4) CRL (Certificate Revocation List) — periodic file listing revoked serial numbers; (5) OCSP (Online Certificate Status Protocol) — real-time revocation checking (faster than CRL but adds an availability dependency); (6) AIA (Authority Information Access) — URLs for fetching issuer certs and CRLs. Validation follows the chain: leaf cert → intermediate CA(s) → root CA, each level verifying the signature of the next — a broken link anywhere invalidates the entire chain.
Common Exam Mistakes in Module 20
Writing MD5 and SHA-1 off as merely old: both are broken for security purposes by practical collision attacks — MD5 collisions have been known for years, SHA-1 fell to SHAttered in 2017. A collision means two different inputs share one digest, which is what makes forged files and certificates possible. New designs use SHA-2 (SHA-256, SHA-512) or BLAKE3; password storage moves to memory-hard functions — bcrypt, scrypt, Argon2.
Inverting how a digital signature works: the sender hashes the message and signs that hash with their own private key; the recipient verifies with the sender's public key. No private key ever travels, and the recipient's key plays no part in the signature — authenticity, integrity, and non-repudiation in one operation.
Missing forward secrecy in any TLS evaluation: with ECDHE, each session negotiates ephemeral keys, so stealing the server's long-term private key later does not decrypt earlier captured traffic — the counter to harvest-now-decrypt-later. A stem asking whether archived captures stay safe after a key compromise is testing exactly this.
Tools Used in Cryptographic Analysis
Cryptographic analysis and assessment tools the CEH v13 exam references, by job:
OpenSSL: open-source cryptography toolkit on virtually every Unix/Linux system — key generation (genrsa, ecparam), certificate work (req, verify, x509 -text), encryption (enc -aes-256-cbc), TLS testing with s_client
Wireshark: protocol analyzer with built-in decryption — decrypts TLS sessions given the browser's session keys, reads IPsec ESP, analyzes the SSH handshake, exposes weak cipher suites and downgrade attempts in captured traffic
FIDO2 / WebAuthn hardware roots: hardware-anchored key storage — TPM on Windows (device attestation, BitLocker keys), Secure Enclave on Apple devices, FIDO2 tokens for passwordless authentication; the exam's modern answer to key management
Worked Example: One Certificate, Read End to End
Take a stem about a site's TLS certificate and walk the PKI: the Registration Authority vets the applicant; the Certificate Authority signs an X.509 certificate binding the site's identity to its public key — subject, issuer, validity period, serial number, CA signature inside. A validating client walks the chain of trust and checks revocation through CRLs or OCSP before trusting anything. The handshake splits by job: the server proves its identity with an asymmetric signature (RSA or ECC) while data transfer runs on fast symmetric AES — ECDHE key agreement supplying fresh ephemeral session keys, which is where perfect forward secrecy comes from.
The twist: the exam's forward-looking fact sits underneath all of it. Shor's algorithm on a sufficiently large quantum computer breaks the mathematics RSA and ECC rest on — efficient factoring and discrete-log solving — which is why NIST is standardizing post-quantum cryptography, led by lattice-based schemes. Grover's algorithm only halves effective symmetric key strength, so AES with longer keys absorbs it; the quantum threat list for a CEH answer is RSA, ECC, and Diffie-Hellman — not the symmetric workhorse.
How to Study Cryptography for the CEH v13 Exam
To effectively study Module 20 for the Certified Ethical Hacker exam:
Create an algorithm reference table: Algorithm | Type (sym/asym/hash) | Key Size | Status (current/deprecated/broken) | Common Use. Include: AES-128/256 (sym, current, bulk encryption), RSA-2048/4096 (asym, current, key exchange + signatures), ECC P-256/P-384 (asym, current, IoT/mobile), ECDHE (key agreement, forward secrecy), SHA-256/384/512 (hash, current), SHA-3 (hash, current), BLAKE2/3 (hash, current), MD5 (hash, BROKEN), SHA-1 (hash, BROKEN for signatures), DES (sym, broken), 3DES (sym, deprecated), RC4 (sym/stream, broken), WPA2-AES (wireless, current standard), WPA3-SAE (wireless, forward secrecy). Stems present a scenario and ask which algorithm is being described or which one is appropriate
Hands-on exercise: with OpenSSL, generate an RSA key pair (openssl genrsa -out private.pem 2048), extract the public key (openssl rsa -in private.pem -pubout -out public.pem), create a self-signed certificate (openssl req -x509 -key private.pem -out cert.pem -days 365), encrypt/decrypt a test file (openssl rsautl -encrypt / -decrypt). Then connect to a website with openssl s_client and examine the TLS handshake: which cipher suite is negotiated, which certificate chain is presented, are deprecated protocols (TLS 1.0/1.1) still offered? This mirrors exam questions about evaluating TLS configurations
Memorize the "broken algorithms" list and why each is broken: MD5 — collision attacks (two different files share a hash → forge signed files); SHA-1 — SHAttered chosen-prefix collision (malicious certificate matching a legitimate one's hash); DES — 56-bit key space brute-forced in hours with modern hardware; RC4 — keystream statistical biases allow plaintext recovery after sufficient ciphertext; WEP — IV reuse + weak CRC32 integrity check allow key recovery from ~40,000 packets. Know each attack name: MD Collide (MD5), SHAttered (SHA-1), rainbow tables/distributed computing (DES/RC4), Flask/d4 protocol (WEP)
Review related modules: Module 6 (System Hacking) for how cryptographic hashes power password storage and cracking (NTLM, Kerberos AES), Module 16 (Wireless Networks) for the WEP→WPA→WPA2→WPA3 evolution with each generation's attack vectors, and Module 12 (Evading IDS/Network Attacks) for how encryption hides malicious traffic from network-based detection. Cryptography is a cross-cutting concern — it appears in nearly every domain
Frequently Asked Questions About Cryptography
What is forward secrecy and which protocols provide it on the CEH exam?
Forward secrecy (Perfect Forward Secrecy, PFS) means each session's encryption keys are derived from ephemeral key material destroyed after the session ends — so even if the server's long-term private key is later obtained, previously captured traffic CANNOT be decrypted. Protocols WITH forward secrecy: (1) DHE (Diffie-Hellman Ephemeral) — RSA key exchange in TLS without DHE does NOT have forward secrecy, because the server's RSA private key can decrypt past sessions; (2) ECDHE (Elliptic Curve DHE Ephemeral) — the modern standard with smaller keys; used in TLS 1.2 (ECDHE-RSA, ECDHE-ECDSA) and the default in TLS 1.3, which provides forward secrecy by design after removing RSA key exchange entirely. WITHOUT: (1) RSA key transport in TLS — the server's long-term RSA key encrypts the session master secret; compromising it decrypts ALL past sessions; (2) static DH (non-ephemeral) — the same shared secret is reused across all sessions with the same parameters. TLS 1.3 mandates forward secrecy by removing static RSA key exchange — a significant improvement over TLS 1.2, where non-forward-secret suites were still negotiable. WPA3 also provides forward secrecy through SAE (Simultaneous Authentication of Equals), using ephemeral Diffie-Hellman for each association. Practical implication: an organization recording all network traffic is at risk on non-forward-secret protocols — future key compromise reveals every recorded session.
How does a Man-in-the-Middle (MITM) attack exploit cryptographic protocols?
A MITM attack intercepts and optionally alters communication between two parties who believe they are talking directly. Cryptographic vectors the exam tests: (1) protocol downgrade — force weaker versions: SSLv3/TLS 1.0 instead of TLS 1.2/1.3 (enables POODLE/BEAST), or CBC instead of GCM; countered by the HSTS header and protocol version enforcement; (2) certificate spoofing — a self-signed or fake certificate is accepted if the client doesn't validate the chain properly (or has the attacker's CA in its trust store); exploited via ARP spoofing on local networks to redirect traffic; (3) key substitution in DH — the attacker establishes separate key exchanges with each party (A↔M and M↔B), decrypting and re-encrypting all traffic; prevented by authenticated DH, where the DH public keys are signed, as in TLS; (4) rogue CA attack — if the trust store includes a compromised or unauthorized CA, any certificate from it is accepted; mitigated by certificate pinning (hardcoded expected public key hash). Detection: monitoring for unexpected certificate changes, certificate transparency logs, HSTS preload lists, and segmentation that prevents rogue access points. The most commonly tested scenario: ARP spoofing on a local network combined with TLS interception using a rogue CA — testing whether the organization validates certificates and uses HSTS.
Related CEH v13 Modules
Module 6: System Hacking — the theoretical foundation for password cracking: NTLM's MD4-based hash and Kerberos ticket encryption enable offline attacks
Module 16: Hacking Wireless Networks — applies cryptography to 802.11, where each generation (WEP through WPA3) fixed a specific cryptographic weakness