lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  PHC 
Open Source and information security mailing list archives
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Date: Mon, 31 Aug 2009 14:25:54 +0300
From: Amit Klein <>
Subject: Writeup by Amit Klein (Trusteer): "Google Chrome 3.0 (Beta) Math.random

Hi list

I would like to announce a new writeup, titled
"Google Chrome 3.0 (Beta) Math.random vulnerability".
The writeup is available in the following URL:

The revised Google Chrome Math.random algorithm (included in version
3.0 of Google Chrome) is predictable. This paper describes how Google
Chrome 3.0 Math.random's internal state can be reconstructed, and how
it can be rolled forward and backward, and how (in Windows) the exact
seeding time can be extracted. This in turn leads to various attacks
(e.g. "in-session phishing") as described in an earlier paper 


Amit Klein, CTO, Trusteer

Powered by blists - more mailing lists