C Sharp Predictable Iv Nonce Source
Description
This detector identifies when C# cryptographic operations use predictable initialization vectors (IVs) or nonces, which compromises the security of encryption algorithms. Using predictable or static IVs makes encrypted data vulnerable to cryptographic attacks, as attackers can exploit patterns in the encrypted output to potentially recover plaintext or encryption keys.
Detection Strategy
• Reports vulnerabilities when cryptographic IV properties are set to predictable values (such as hardcoded bytes, zero arrays, or deterministic patterns)
• Flags CreateEncryptor method calls that use predictable or static initialization vectors instead of cryptographically secure random values
• Detects AEAD (Authenticated Encryption with Associated Data) encrypt operations that employ predictable nonces, which violates the fundamental security requirement that nonces must be unique for each encryption operation
Vulnerable code example
using System;
using System.Security.Cryptography;
using System.Text;
public class PredictableIvExample
{
public void VulnerableEncryption()
{...✅ Secure code example
using System;
using System.Security.Cryptography;
using System.Text;
public class PredictableIvExample
{
public void SecureEncryption()
{...Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.