uuid-insecurities.md (4804B)
1 --- 2 title: "UUID Insecurities" 3 section: "Web Pentesting" 4 sectionSlug: "pentesting-web" 5 sourcePath: "src/pentesting-web/uuid-insecurities.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/uuid-insecurities.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # UUID Insecurities 14 15 ## Basic Information 16 17 Universally Unique Identifiers (UUIDs) are **128-bit numbers used to uniquely identify information** in computer systems. UUIDs are essential in applications where unique identifiers are necessary without central coordination. They are commonly used as database keys and can refer to various elements like documents and sessions.<sup>[[1]](#references)</sup> 18 19 UUIDs are designed primarily for uniqueness, **not secrecy or authorization**. Some versions are predictable, and even a random UUID must not replace an access-control check. The conventional text form contains 32 hexadecimal digits in five groups.<sup>[[2]](#references)</sup> 20 21 - **UUID v1** is time-based, incorporating a timestamp, clock sequence, and node value; implementations may use a MAC address and expose system information. 22 - **UUID v2** is a DCE Security variant derived from v1 and is not specified by current RFC 9562. 23 - **UUID v3 and v5** generate UUIDs using hash values from namespace and name, with v3 using MD5 and v5 using SHA-1. 24 - **UUID v4** carries 122 random bits when produced by a conforming cryptographically secure generator. Guessing risk depends on generator quality and token lifetime, not only the nominal format.<sup>[[2]](#references)</sup> 25 26 > [!TIP] 27 > The version and **variant** occupy fixed bit positions in RFC UUIDs. For example:\ 28 > 12345678 - abcd - 1a56 - a539 - 103755193864\ 29 > xxxxxxxx - xxxx - Mxxx - Nxxx - xxxxxxxxxxxx 30 > 31 > - The **position of `M`** indicates the UUID **version**. In the example above, it is UUID v**1**. 32 > - The **position of `N`** indicates the UUID variant. 33 34 ## Sandwich attack 35 36 The "Sandwich Attack" is a specific type of attack that **exploits the predictability of UUID v1 generation in web applications**, particularly in features like password resets. UUID v1 is generated based on time, clock sequence, and the node's MAC address, which can make it somewhat predictable if an attacker can obtain some of these UUIDs generated close in time.<sup>[[1]](#references)</sup> 37 38 ### Example 39 40 Imagine a web application that uses UUID v1 for generating password reset links. Here’s how an attacker might exploit this to gain unauthorized access: 41 42 1. **Initial Setup**: 43 44 - The attacker has control over two email accounts: \`attacker1@acme.com\` and \`attacker2@acme.com\`. 45 - The target's email account is \`victim@acme.com\`. 46 47 2. **Execution**: 48 49 - The attacker triggers a password reset for their first account (\`attacker1@acme.com\`) and receives a password reset link with a UUID, say \`99874128-7592-11e9-8201-bb2f15014a14\`. 50 - Immediately after, the attacker triggers a password reset for the victim's account (\`victim@acme.com\`) and then quickly for the second attacker-controlled account (\`attacker2@acme.com\`). 51 - The attacker receives a reset link for the second account with a UUID, say \`998796b4-7592-11e9-8201-bb2f15014a14\`. 52 53 3. **Analysis**: 54 55 - The attacker now has two UUIDs generated close in time (\`99874128\` and \`998796b4\`). Given the sequential nature of time-based UUIDs, the UUID for the victim's account will likely fall between these two values. 56 57 4. **Brute Force Attack:** 58 59 - The attacker uses a tool to generate UUIDs between these two values and tests each generated UUID by attempting to access the password reset link (e.g., \`https://www.acme.com/reset/\<generated-UUID>\`). 60 - If the web application does not adequately rate limit or block such attempts, the attacker can quickly test all possible UUIDs in the range. 61 62 5. **Access Gained:** 63 64 - Once the correct UUID for the victim's password reset link is discovered, the attacker can reset the victim's password and gain unauthorized access to their account. 65 66 ### Tools 67 68 - The `sandwich` tool automates candidate generation between two observed UUIDv1 values.<sup>[[3]](#references)</sup> 69 - Burp Suite's UUID Detector extension identifies UUIDs and highlights their version/variant during proxy analysis.<sup>[[4]](#references)</sup> 70 71 ## References 72 73 - [1] [VerSprite - Universally Unique Identifiers](https://versprite.com/blog/universally-unique-identifiers/) 74 - [2] [RFC 9562 — Universally Unique IDentifiers (UUIDs)](https://www.rfc-editor.org/rfc/rfc9562.html) 75 - [3] [Lupin-Holmes/sandwich](https://github.com/Lupin-Holmes/sandwich) 76 - [4] [PortSwigger BApp Store — UUID Detector](https://portswigger.net/bappstore/65f32f209a72480ea5f1a0dac4f38248)