Bugtraq mailing list archives
Re: Jetty Session ID Prediction
From: Michal Zalewski <lcamtuf () dione ids pl>
Date: Tue, 6 Feb 2007 09:20:33 +0100 (CET)
On Tue, 6 Feb 2007, Amit Klein wrote:
I don't think that the method described in the paper you referenced above is applicable as-is [...] (only 32 bits out of the 48 are known).
There are attacks published for just about any variant of LCG imaginable, including ones with missing MSB/LSB output bits, etc. But I had a chance to talk to David Litchfield and Chris Anley off the list, and they do use an algorithmic approach, not brute force - that was simply a poor choice of words. /mz
Current thread:
- Jetty Session ID Prediction NGSSoftware Insight Security Research (Feb 05)
- Re: Jetty Session ID Prediction Amit Klein (Feb 05)
- Re: Jetty Session ID Prediction Michal Zalewski (Feb 05)
- Re: Jetty Session ID Prediction Amit Klein (Feb 06)
- Re: Jetty Session ID Prediction Michal Zalewski (Feb 06)
- Re: Jetty Session ID Prediction Amit Klein (Feb 06)
- <Possible follow-ups>
- Re: Jetty Session ID Prediction Chris Anley (Feb 06)
- Re: Jetty Session ID Prediction Amit Klein (Feb 06)
- Re: Jetty Session ID Prediction Chris Anley (Feb 07)
- Re: Jetty Session ID Prediction Michal Zalewski (Feb 06)
- Re: Jetty Session ID Prediction Amit Klein (Feb 06)