Collected research
[EN] Unsecure time-based secret and Sandwich Attack
[EN] Unsecure time-based secret and Sandwich Attack - Analysis of my research and release of the “Reset Tolkien” tool
Password-reset tokens built from PHP uniqid(), time(), UUIDv1 or MongoDB ObjectIDs are recoverable because the HTTP Date header reveals the request instant, and hashing them in md5 or sha256 only means the attacker recomputes the hash of each candidate timestamp. Three sequential requests - attacker, victim, attacker - bound the victim's token between two known ones, and the Reset Tolkien tool detects the format and enumerates the range against a validity oracle.
Record
- Document
- [EN] Unsecure time-based secret and Sandwich Attack - Analysis of my research and release of the “Reset Tolkien” tool
- Published by
- aeth.cc
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of aeth.cc, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .