|
Articles
|
|
 |
Insecure Randomness
Insecure Randomness
Abstract
Standard pseudo-random number generators cannot withstand cryptographic attacks.
Description
Insecure randomness...
|
|
08 May, 2008
Views: 285
|
|
 |
J2EE Misconfiguration: Insufficient Session-ID Length
J2EE Misconfiguration: Insufficient Session-ID Length
Abstract
Session identifiers should be at least 128 bits long to prevent brute-force session...
|
|
08 May, 2008
Views: 328
|
|
 |
Key exchange without entity authentication
Key exchange without entity authentication
Overview
Performing a key exchange without verifying the identity of the entity being communicated with...
|
|
08 May, 2008
Views: 260
|
|
 |
Non-cryptographic pseudo-random number generator
Non-cryptographic pseudo-random number generator
Overview
The use of Non-cryptographic Pseudo-Random Number Generators (PRNGs) as a source for...
|
|
08 May, 2008
Views: 267
|
|
 |
Not using a random initialization vector with cipher block chaining mode
Not using a random initialization vector with cipher block chaining mode
Overview
Not using a random initialization vector with Cipher Block...
|
|
08 May, 2008
Views: 285
|
|
 |
Reusing a nonce, key pair in encryption
Reusing a nonce, key pair in encryption
Overview
Nonces should be used for the present occasion and only once.
Consequences
...
|
|
08 May, 2008
Views: 252
|
|
 |
Testing for SSL-TLS
Testing for SSL-TLS
Brief Summary
Due to historical exporting restrictions of high grade cryptography, legacy and new web servers could be able...
|
|
08 May, 2008
Views: 320
|
|
 |
Use of hard-coded cryptographic key
Use of hard-coded cryptographic key
Overview
The use of a hard-coded cryptographic key tremendously increases the possibility that encrypted data...
|
|
08 May, 2008
Views: 258
|
|
 |
Use of hard-coded cryptographic key
Use of hard-coded cryptographic key
Overview
The use of a hard-coded cryptographic key tremendously increases the possibility that encrypted data...
|
|
08 May, 2008
Views: 245
|
|
 |
Using a broken or risky cryptographic algorithm
Using a broken or risky cryptographic algorithm
Overview
The use of a broken or risky cryptographic algorithm is an unnecessary risk that may...
|
|
08 May, 2008
Views: 254
|
|