Insecure random-number generation

Insecure random-number generation

Description

rand, mt_rand, uniqid, and str_shuffle are unsuitable for generating security tokens or authentication codes.

Potential impact

Predictable values may allow token guessing, authentication bypass, or session hijacking.

Remediation

Use random_bytes or random_int for security-sensitive random values.

Examples

Before

php
<?php
$token = uniqid();

After

php
<?php
$token = bin2hex(random_bytes(32));

Explanation:

  • Before: A predictable generator is used for a security-sensitive token.
  • After: The token is generated from cryptographically secure random bytes.

References