cd /var/tmp;
When I see things like this it makes me think that if standard paths weren't used, then it would it at least make things a little more interesting for the hacker. (They'd have to find a location first.)
When I see things like this it makes me think that if standard paths weren't used, then it would it at least make things a little more interesting for the hacker. (They'd have to find a location first.)
find / -maxdepth 3 -perm -7 -type d -print
and tweak as needed. # time find / -maxdepth 3 -perm -7 -type d -print
/tmp
/var/tmp
real 0m0.034s
user 0m0.005s
sys 0m0.028s
This was run on a pretty anemic VPS. Might have to up the depth to 4 if it doesn't return anything, but IMO that's pretty unlikely.I'm perfectly aware that this could be "extremely difficult" or "not feasible" in many situations, but it wouldn't be so hard to control if you made the device and designed the OS for it (linux-based routers, etc.). I'm just tired of people giving up and laying things out like a holiday dinner because it's "too difficult". Good security requires sacrifice of work and time.
Anything that can be obfuscated programatically (while still remaining usable) can be rediscovered programatically. This accomplishes nothing.