# Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) (CWE-338) The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong. **Stack:** Go - Prevalence: 높음 자주 악용됨 - Impact: 높음 2개의 높은 심각도 규칙 - Prevention: 문서화됨 4개의 수정 예시 **OWASP:** Cryptographic Failures (A02:2021-Cryptographic Failures) - #2 ## Description When a non-cryptographic PRNG is used in a security context (such as generating session tokens or cryptographic keys), an attacker may be able to predict its output and compromise the security mechanism. ## Prevention 1개의 Shoulder 탐지 규칙을 기반으로 한 Weak PRNG 예방 전략. ### Go Use crypto/rand instead of math/rand for security-sensitive values ## Warning Signs - [HIGH] math/rand used for security-sensitive random values ## Consequences - 보호 메커니즘 우회 - 권한 획득 ## Mitigations - 암호학적으로 안전한 난수 생성기(CSPRNG)를 사용하세요 - JavaScript에서는 crypto.getRandomValues() 또는 crypto.randomUUID()를 사용하세요 - Python에서는 random 대신 secrets 모듈을 사용하세요 ## Detection - Total rules: 4 - Languages: go, javascript, typescript, python ## Rules by Language ### Go (1 rules) - **Weak Random Number Generation for Security** [HIGH]: Uses math/rand for security tokens, keys, or session IDs instead of crypto/rand. - Remediation: Use crypto/rand for all security-sensitive random values. ```go import "crypto/rand" token := make([]byte, 32) if _, err := rand.Read(token); err != nil { return err } ``` Learn more: https://shoulder.dev/learn/go/cwe-338/weak-random