Collected research
phpwn: Attack on PHP sessions and random numbers
Attack on PHP Sessions and Random Numbers
PHP 5.3.1 and earlier seed their linear congruential generator weakly enough that the 64-bit seed reduces to 35 bits, or under 20 bits given code execution, recoverable in seconds. That makes session IDs and lcg_value() output predictable. The page runs a live demo against the visitor and ships C tools to solve the LCG forwards and backwards and to derive session IDs.
Record
- Document
- Attack on PHP Sessions and Random Numbers
- Researcher
- Samy Kamkar
- Published by
- samy.pl
- Topic
- Identity
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Samy Kamkar, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .