A "differential" attack on Polly Cracker

We describe an attack on the cryptosystem Polly Cracker for which it is not necessary to know a superset of the monomials used during encryption. The attack is demonstrated with Koblitz's "graph perfect code instance" of Polly Cracker.