Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Web Application Security
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Ruining Security with java.util.Random Dec 17 2006 12:19AM
Jan P. Monsch (jan monsch iplosion com)
Hi

In my review practice I often have to look at Java source code which is used
to generate passwords, authentication tokens or session ids. Ever so often
this code uses the Java API class java.util.Random to generate random
numbers. It is well-established in security industry that this particular
...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus