Tags: lcg crypto dsa 

Rating:

Correct DSA algorith with insecure LCG for generating k. Because each k is linearly related to consecutive signatures, one can set up a system of equations to solve for k and x, the key.

Original writeup (https://github.com/Lyusternik/CTFWriteups/tree/master/VolgaCTF2018).