On the weakness of constant blinding PRNG in flash player

1Citations
Citations of this article
9Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Constant blinding is considered an effective mitigation against JIT spray attacks. In this paper, we study the design and implementation of constant blinding mechanism in Flash Player and analyse the weakness in its pseudo random number generator (PRNG). We demonstrate how such weakness can be exploited to recover the seed value in PRNG, thus bypass the constant blinding in Flash Player. We propose two methods to circumvent constant blinding in Flash Player. The first method aims at recovering the seed value using cryptanalysis on the PRNG algorithm, which turns out to provide only 21-bit entropy. The second method focuses on ill-considered implementation of PRNG, which puts obvious signature value next to the seed value and makes it easy for attacker to search. To demonstrate the two methods are both practical, we present proof-of-concept attacks based on existing vulnerability. We have reported the issue to Adobe Flash security team and CVE-2017–3000 is assigned to us. To the best of our knowledge, we are the first to analyse the randomness in constant blinding and integrate cryptanalysis in constant blinding bypass. Furthermore, we implement a prototype tool Constant Blinding Enhancement (ConBE) based on dynamic instrumentation framework to defend against our proposed attacks. In ConBE, we provide a stronger defence than the official patch of Flash Player.

Cite

CITATION STYLE

APA

Wang, C., Huang, T., & Wu, H. (2018). On the weakness of constant blinding PRNG in flash player. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 11149 LNCS, pp. 107–123). Springer Verlag. https://doi.org/10.1007/978-3-030-01950-1_7

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free