Web Hack List

Collected research

phpwn: Attack on PHP sessions and random numbers

Attack on PHP Sessions and Random Numbers

PHP 5.3.1 and earlier seed their linear congruential generator weakly enough that the 64-bit seed reduces to 35 bits, or under 20 bits given code execution, recoverable in seconds. That makes session IDs and lcg_value() output predictable. The page runs a live demo against the visitor and ships C tools to solve the LCG forwards and backwards and to derive session IDs.

Record

Document
Attack on PHP Sessions and Random Numbers
Researcher
Samy Kamkar
Published by
samy.pl
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Samy Kamkar, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .