OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Is /tmp still appropriate? (was Re: [hacksware]Pine temporary file hijacking vulnerability)
From: stanislav shalunov (shalunovINTERNET2.EDU)
Date: Mon Dec 18 2000 - 19:29:13 CST


Michael Damm <mikedACCESSNW.NET> writes:

> I alwas was a difficult child.
> TMPKEY="$RANDOM"
> echo "foo" >/tmp/blah.$TMPKEY

This is actually a single linear transform of PID+NOW into 16-bit
space (((pid+now)*1103515245 + 12345) & 32767). Trivial guess.

--
Stanislav Shalunov <shalunovinternet2.edu>	Internet Engineer, Internet2

A fool's brain digests philosophy into folly, science into superstition, and art into pedantry. Hence University education. -- G. B. Shaw