![]() |
|
No such thing as a small change | |
PerlMonks |
Re^4: Debugging cgi-bin scriptby Anonymous Monk |
on Jan 06, 2013 at 09:10 UTC ( #1011856=note: print w/replies, xml ) | Need Help?? |
Designing your own random number generator in a high-level language is a terrible, terrible idea. :) FWIW, merlyn didn't design it, he copied from the fallback Apache::Session::Generate::MD5 I don't know from entrophy and randomness, but this isn't encryption we're dealing with, no authentication or authorization, no financial transactions -- if the attacker has access to the application, guessing doesn't get him anything he didn't already have access to You might like Re^3: Randomness encountered with CGI Session where afoken talks bits FYI/FMI Session::Token - Portable, secure, efficient, simple random session token generation that satisfies those OWASP recommendations
In Section
Seekers of Perl Wisdom
|
|