Sec Bug->Doc #62966 [Ana]: Random numbers prediction

From: Date: Wed, 28 Nov 2012 15:31:12 +0000
Subject: Sec Bug->Doc #62966 [Ana]: Random numbers prediction
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-9220@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=62966&edit=1 ID: 62966 Updated by: pajoye@php.net Reported by: ymaryshev at ptsecurity dot ru Summary: Random numbers prediction Status: Analyzed -Type: Security +Type: Documentation Problem Package: *General Issues Operating System: All PHP Version: Irrelevant Block user comment: N Private report: Y New Comment: Doc needs to be updated to add the security concerns about the rand and mt_rand set of functions. Previous Comments: ------------------------------------------------------------------------ [2012-11-28 13:44:37] ymaryshev at ptsecurity dot ru Fixed issue summary ------------------------------------------------------------------------ [2012-09-20 10:45:53] ymaryshev at ptsecurity dot ru By stronger seeding we mean: 1. Use external sources of entropy as in case of PHPSESSID in newer PHP versions (php_win32_get_random_bytes, urandom, etc). In other words we suggest applying “session.entropy_file/entropy_length” to the seed generating functions, namely lcg_seed() and GENERATE_SEED() 2. Do not use the output of the LCG for generating seed of (mt_)rand (in the GENERATE_SEED macro) ------------------------------------------------------------------------ [2012-09-19 14:21:30] tony2001@php.net How do you propose to fix it in PHP? "Stronger seeding" sounds a bit too general to me. ------------------------------------------------------------------------ [2012-09-06 10:00:48] ymaryshev at ptsecurity dot ru We certainly do not object to it, but we still think that fixing this problem would be a more appropriate solution just for the sake of web apps which do not track recent changes in PHP documentation. ------------------------------------------------------------------------ [2012-09-05 09:43:17] pajoye@php.net [2012-09-05 08:15 UTC] ymaryshev at ptsecurity dot ru [delete] > We have checked the manual pages for rand, mt_rand and uniqid > functions and only the latter has a security related notice. Ok, then let fix that by adding these notices in the rand functions too. > Our research of different web apps shows that the developers > do not know the risks of using uniqid and (mt_)rand together. > We really urge you to examine carefully the attack scenario > that we described in earlier messages. The “more_entropy” > argument of uniqid is misleading as it allows to predict > the numbers generated by (mt_)rand. If this is an appropriate > behavior of PHP then it should be mentioned in documentation, > otherwise it should be fixed. It should be fixed anyway, not PHP but the applications. They actually should use openssl_random_pseudo_bytes or urandom (or the like) when available. Drupal or many other major applications already made this move when the 1st attacks was done using simple brute force prediction a couple of years ago. If nobody objects, I will make this bug public by Monday, and mark as a documentation problem. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=62966 -- Edit this bug report at https://bugs.php.net/bug.php?id=62966&edit=1

« previous php.doc.bugs (#9220) next »