I Forgot Your Password: Randomness Attacks Against PHP Applications

George Argyros, Aggelos Kiayias

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

We provide a number of practical techniques and algorithms for exploiting randomness vulnerabilities in PHP applications.We focus on the predictability of password reset tokens and demonstrate how an attacker can take over user accounts in a web application via predicting or algorithmically derandomizing the PHP core randomness generators. While our techniques are designed for the PHP language, the principles behind our techniques and our algorithms are independent of PHP and can readily apply to any system that utilizes weak randomness generators or low entropy sources. Our results include: algorithms that reduce the entropy of time variables, identifying and exploiting vulnerabilities of the PHP system that enable the recovery or reconstruction of PRNG seeds, an experimental analysis of the Håstad-Shamir framework for breaking truncated linear variables, an optimized online Gaussian solver for large sparse linear systems, and an algorithm for recovering the state of the Mersenne twister generator from any level of truncation. We demonstrate the gravity of our attacks via a number of case studies. Specifically, we show that a number of current widely used web applications can be broken using our techniques including Mediawiki, Joomla, Gallery, osCommerce and others.
Original languageEnglish
Title of host publicationProceedings of the 21th USENIX Security Symposium, Bellevue, WA, USA, August 8-10, 2012
PublisherUsenix
Pages81-96
Number of pages16
Publication statusPublished - 2012

Fingerprint

Dive into the research topics of 'I Forgot Your Password: Randomness Attacks Against PHP Applications'. Together they form a unique fingerprint.

Cite this