24.11.2016 Views

Not So Random

Not%20So%20Random%20-%20Exploiting%20Unsafe%20Random%20Number%20Generator%20Use

Not%20So%20Random%20-%20Exploiting%20Unsafe%20Random%20Number%20Generator%20Use

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Practical Exploitation - Tips<br />

• Load balancing can be an issue; multiple application servers will<br />

cause multiple PRNGs to be generating output.<br />

• Use Persistent HTTP connections to force same process<br />

• Connection: Keep-Alive<br />

• <strong>Not</strong> covered in this talk, but state recovery attacks are also a<br />

possibility against PRNGs given enough output<br />

<strong>Not</strong> <strong>So</strong> <strong>Random</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!