Php Key Derived Iv Nonce
Description
Detects when cryptographic initialization vectors (IV) or nonces are derived from encryption keys in PHP applications. This vulnerability weakens encryption security because predictable or key-derived IVs can allow attackers to recover plaintext or detect patterns in encrypted data, violating cryptographic best practices that require random, unique IVs.
Detection Strategy
• Scans PHP source code for cryptographic function calls from OpenSSL or PHPSecLib libraries
• Identifies function calls where initialization vectors or nonces appear to be derived from the same cryptographic key being used for encryption
• Triggers when the analysis detects that IV/nonce generation depends on or derives from the encryption key rather than using secure random generation
• Reports vulnerabilities in both native OpenSSL functions and third-party PHPSecLib cryptographic operations that exhibit this insecure pattern
Vulnerable code example
<?php
use phpseclib3\Crypt\AES;
function encryptWithSameKeyAsIV($data) {
$key = random_bytes(16);
// VULNERABLE: IV reuses the same bytes as the encryption key
return openssl_encrypt($data, 'aes-128-cbc', $key, OPENSSL_RAW_DATA, $key);
}...✅ Secure code example
<?php
use phpseclib3\Crypt\AES;
function encryptWithSameKeyAsIV($data) {
$key = random_bytes(16);
// SAFE: Generate random IV instead of reusing key
$iv = random_bytes(16);
return openssl_encrypt($data, 'aes-128-cbc', $key, OPENSSL_RAW_DATA, $iv);...Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.