[security]KVE-2026-0693 비밀번호 재설정 토큰 예측 가능 취약점 수정

rand() 대신 CSPRNG 기반 get_random_token_string() 사용
- mb_nonce: 128비트 CSPRNG 토큰으로 시드 브루트포스 차단
- change_password: CSPRNG 기반 10자리 hex로 변경

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
thisgun
2026-04-16 03:39:12 +00:00
co-authored by Claude Opus 4.6
parent 5875e8b86b
commit 7d8a660642
+4 -4
View File
@@ -36,12 +36,12 @@ if (empty($mb['mb_id']) || $mb['mb_leave_date'] || is_admin($mb['mb_id'])) {
alert_close($generic_message);
}
// 임시비밀번호 발급
$change_password = rand(100000, 999999);
// 임시비밀번호 발급 (CSPRNG 사용)
$change_password = get_random_token_string(5); // 10자리 hex (0-9, a-f)
$mb_lost_certify = get_encrypt_string($change_password);
// 어떠한 회원정보도 포함되지 않은 일회용 난수를 생성하여 인증에 사용
$mb_nonce = md5(pack('V*', rand(), rand(), rand(), rand()));
// 어떠한 회원정보도 포함되지 않은 일회용 난수를 생성하여 인증에 사용 (CSPRNG 사용)
$mb_nonce = get_random_token_string(16);
// 임시비밀번호와 난수를 mb_lost_certify 필드에 저장
$sql = " update {$g5['member_table']} set mb_lost_certify = '$mb_nonce $mb_lost_certify' where mb_id = '{$mb['mb_id']}' ";