24.11.2016 Views

Not So Random

Not%20So%20Random%20-%20Exploiting%20Unsafe%20Random%20Number%20Generator%20Use

Not%20So%20Random%20-%20Exploiting%20Unsafe%20Random%20Number%20Generator%20Use

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Exploitation Theory<br />

Target PRNG<br />

Obtain internal state<br />

from known output<br />

Output<br />

K1aQdFbhmQoj67Lbba9qzknk<br />

qhR5jXwz<br />

rrEahOjVbA7cK4ZwmG9KsERV<br />

NQ8WMq19<br />

97sRz0OYI4CfE5JBrb3B9068<br />

bXA02Mle<br />

mSNj01w16M7nb5o42NjDYcwU<br />

tcSyFwJd<br />

Use<br />

Known Password Reset Token<br />

Known Password Reset Token<br />

Known Password Reset Token<br />

Known Password Reset Token<br />

???????????????????? Target Password Reset Token<br />

<strong>Not</strong> <strong>So</strong> <strong>Random</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!