OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Bugtraq archives for 4th quarter (Oct-Dec) 1998: Re: DCC HiJacking patch for BitchX 75p1

Re: DCC HiJacking patch for BitchX 75p1

Andy Dills (andySS5.XECU.NET)
Mon, 21 Dec 1998 16:27:13 -0500

On Sun, 18 Oct 1998, Alessio Orlandi wrote:

> the ports will be quiet consecutive. Bad.. Bad... So.. let's add a
> random value to the port returned by the system. All is now fixed.
> Patch follows

Your patch changes the order, but there is still order.

You need to call srand() once before using rand, to ensure actual
randonimity.

Andy
--
System Administrator
XecuNet Internet Services