Re: Jetty Session ID Prediction
- From: Michal Zalewski <lcamtuf@xxxxxxxxxxxx>
- Date: Tue, 6 Feb 2007 19:10:49 +0100 (CET)
On Tue, 6 Feb 2007, Chris Anley wrote:
http://www.ngssoftware.com/research/papers/Randomness.pdf
Nice paper, and quite certainly helpful for security testers as far as
showing the weakness of standard library PRNGs to others goes.
The idea is eventually to have a tool that performs point-and-click
identification, analysis and prediction of an unknown source of
"randomness", including LCGs but also more advanced generators such as
the Mersenne twister and SHA1PRNG.
Now not that I want to be obtrusive than I already am (hi mom!), but
http://lcamtuf.coredump.cx/stompy.tgz can very well tell LCGs from
SHA1PRNGs - that and do a bunch of other tricks ;-)
/mz
- References:
- Re: Jetty Session ID Prediction
- From: Chris Anley
- Re: Jetty Session ID Prediction
- Prev by Date: Re: Jetty Session ID Prediction
- Next by Date: [security bulletin] HPSBUX02181 SSRT061289 rev.2 - HP-UX Running IPFilter, Remote Unauthorized Denial of Service (DoS)
- Previous by thread: Re: Jetty Session ID Prediction
- Next by thread: TSLSA-2007-0005 - multi
- Index(es):