logo

Database

C Sharp Predictable Iv Nonce Source

Description

This detector identifies when C# cryptographic operations use predictable initialization vectors (IVs) or nonces, which compromises the security of encryption algorithms. Using predictable or static IVs makes encrypted data vulnerable to cryptographic attacks, as attackers can exploit patterns in the encrypted output to potentially recover plaintext or encryption keys.

Weakness:

395 - Insecure generation of random numbers - Static IV

Category: Functionality Abuse

Detection Strategy

    • Reports vulnerabilities when cryptographic IV properties are set to predictable values (such as hardcoded bytes, zero arrays, or deterministic patterns)

    • Flags CreateEncryptor method calls that use predictable or static initialization vectors instead of cryptographically secure random values

    • Detects AEAD (Authenticated Encryption with Associated Data) encrypt operations that employ predictable nonces, which violates the fundamental security requirement that nonces must be unique for each encryption operation

Vulnerable code example

using System;
using System.Security.Cryptography;
using System.Text;

public class PredictableIvExample
{
    public void VulnerableEncryption()
    {...

✅ Secure code example

using System;
using System.Security.Cryptography;
using System.Text;

public class PredictableIvExample
{
    public void SecureEncryption()
    {...