Collected research
In GUID We Trust
Version 1 UUIDs encode a timestamp, a constant clock sequence and a MAC-derived node ID instead of random data. An attacker who obtains one GUID from an account they control can recover those fields and enumerate every GUID the server could have generated around a victim password reset, guessing the token and taking over the account.
Record
- Researcher
- Daniel Thatcher
- Published by
- intruder.io
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Daniel Thatcher, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .