Sec Bug->Doc #62966 [Ana]: Random numbers prediction
| From: | pajoye@php.net | Date: | Wed, 28 Nov 2012 15:31:12 +0000 |
| Subject: | Sec Bug->Doc #62966 [Ana]: Random numbers prediction | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-9220@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=62966&edit=1
ID: 62966
Updated by: pajoye@php.net
Reported by: ymaryshev at ptsecurity dot ru
Summary: Random numbers prediction
Status: Analyzed
-Type: Security
+Type: Documentation Problem
Package: *General Issues
Operating System: All
PHP Version: Irrelevant
Block user comment: N
Private report: Y
New Comment:
Doc needs to be updated to add the security concerns about the rand and mt_rand
set of functions.
Previous Comments:
------------------------------------------------------------------------
[2012-11-28 13:44:37] ymaryshev at ptsecurity dot ru
Fixed issue summary
------------------------------------------------------------------------
[2012-09-20 10:45:53] ymaryshev at ptsecurity dot ru
By stronger seeding we mean:
1. Use external sources of entropy as in case of PHPSESSID in newer PHP
versions (php_win32_get_random_bytes, urandom, etc). In other words we suggest
applying âsession.entropy_file/entropy_lengthâ to the seed generating functions,
namely lcg_seed() and GENERATE_SEED()
2. Do not use the output of the LCG for generating seed of (mt_)rand (in the
GENERATE_SEED macro)
------------------------------------------------------------------------
[2012-09-19 14:21:30] tony2001@php.net
How do you propose to fix it in PHP?
"Stronger seeding" sounds a bit too general to me.
------------------------------------------------------------------------
[2012-09-06 10:00:48] ymaryshev at ptsecurity dot ru
We certainly do not object to it, but we still think that fixing this problem
would be a more appropriate solution just for the sake of web apps which do not
track recent changes in PHP documentation.
------------------------------------------------------------------------
[2012-09-05 09:43:17] pajoye@php.net
[2012-09-05 08:15 UTC] ymaryshev at ptsecurity dot ru [delete]
> We have checked the manual pages for rand, mt_rand and uniqid
> functions and only the latter has a security related notice.
Ok, then let fix that by adding these notices in the rand functions too.
> Our research of different web apps shows that the developers
> do not know the risks of using uniqid and (mt_)rand together.
> We really urge you to examine carefully the attack scenario
> that we described in earlier messages. The âmore_entropyâ
> argument of uniqid is misleading as it allows to predict
> the numbers generated by (mt_)rand. If this is an appropriate
> behavior of PHP then it should be mentioned in documentation,
> otherwise it should be fixed.
It should be fixed anyway, not PHP but the applications. They actually should use
openssl_random_pseudo_bytes
or urandom (or the like) when available. Drupal or many other major applications already made this
move when
the 1st attacks was done using simple brute force prediction a couple of years ago.
If nobody objects, I will make this bug public by Monday, and mark as a documentation problem.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=62966
--
Edit this bug report at https://bugs.php.net/bug.php?id=62966&edit=1