Skip to navigation
Latest News

Window's random number generator not random enough

By Matthew Sparkes

Posted on 14 Nov 2007 at 10:23

A flaw in the way that random numbers are generated in Windows could enable hackers to predict SSL keys, laying browsing, email and IM communications open to interception.

The research, carried out at the University of Haifa in Israel, was conducted on Windows 2000, but it is likely that the same method is used to create random numbers in XP and Vista.

"We reconstructed, for the first time, the algorithm used by the pseudo-random number generator. We analysed the security of the algorithm and found a non-trivial attack: given the internal state of the generator, the previous state can be computed," says the the research paper.

Predicting future random numbers relies on knowing the initial state of the stack. Once this is known, it is possible to predict up to 128kb of output from the generator, after which Windows refreshes the state of the generator.

"We also analysed the way in which the generator is run by the operating system, and found that it amplifies the effect of the attacks: The generator is run in user mode rather than in kernel mode, and therefore it is easy to access its state even without administrator privileges."

The research claims that a simple buffer overflow could be used to obtain the value of the stack, which could then be used to predict future SSL keys.

Subscribe to PC Pro magazine. We'll give you 3 issues for £1 plus a free gift - click here

From around the web

Be the first to comment this article

You need to Login or Register to comment.

(optional)

advertisement

Most Commented News Stories
More From PC Pro
Latest Blog Posts Subscribe to our RSS Feeds
Latest ReviewsSubscribe to our RSS Feeds
Latest Real World Computing

advertisement

Sponsored Links
 
SEARCH
SIGN UP

Your email:

Your password:

remember me

advertisement


Hitwise Top 10 Website 2010
 
 

PCPro-Computing in the Real World Printed from www.pcpro.co.uk

Register to receive our regular email newsletter at http://www.pcpro.co.uk/registration.

The newsletter contains links to our latest PC news, product reviews, features and how-to guides, plus special offers and competitions.