1 of 30

Practical Exploitation of Insecure Randomness

Breaking V8’s Math.random, practically

2 of 30

whoami

  • Currently: Security Engineer at Cruise
  • Previously: AppSec at Dropbox
  • Very nerd snipe-able

@d0nutptr

3 of 30

4 of 30

5 of 30

Math.random: Under the hood

6 of 30

Math.random: Under the hood

7 of 30

Prior Work?

8 of 30

Prior Work?

9 of 30

Prior Work?

10 of 30

Z3

11 of 30

Z3 in action

12 of 30

So plug-in XS128+ and solve??

13 of 30

Challenge 1: Math.floor

14 of 30

Challenge 1: Math.floor

15 of 30

Adding Math.floor to the solver

16 of 30

Symbolically Perform XS128+

17 of 30

Calculate the u64 (converted to a double later)

18 of 30

Tell Z3 that this should equal the next known value

Expected, known value

From previous slide

19 of 30

Simulating Math.floor in Z3 - IEEE 754 😰

20 of 30

Simulating Math.floor (by cheating)

  1. We can ignore the sign (msb)
  2. Exponent MUST be equal to 1023 (not 100% true.. but we’ll ignore that)

21 of 30

Simulating Math.floor in Z3

22 of 30

Challenge 2: Double Trouble

23 of 30

Sept 24, 2018

24 of 30

Problem 3: Cache miss-take

25 of 30

How Math.random *REALLY* works...

26 of 30

How Math.random *REALLY* works...

27 of 30

How Math.random *REALLY* works...

28 of 30

Implications?

  • We need to reverse our inputs
  • Sometimes inputs can cross cache-fill events

29 of 30

Enough Theory, Let’s do a Demo

30 of 30

My Socials

@d0nutptr

@d0nutptr