Other nomination
[EN] Unsecure time-based secret and Sandwich Attack
Password-reset tokens built from PHP uniqid(), time(), UUIDv1 or MongoDB ObjectIDs are recoverable because the HTTP Date header reveals the request instant, and hashing them in md5 or sha256 only means the attacker recomputes the hash of each candidate timestamp. Three sequential requests - attacker, victim, attacker - bound the victim's token between two known ones, and the Reset Tolkien tool detects the format and enumerates the range against a validity oracle.
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.