Re: Non-executable stack

jimmy_at_inet-solutions.be
Date: 10/27/05

  • Next message: Darren Reed: "Re: ipf stopped working on 5.3"
    Date: Thu, 27 Oct 2005 08:35:31 +0200
    To: db <db@traceroute.dk>
    
    

    Quoting db <db@traceroute.dk>:

    > Hi all
    >
    > Does FreeBSD support a non-executable stack on any of the tier 1 and 2
    > platforms that has this feature?
    > If not, are there any plans of implementing this and is there a patch I can
    > use for 6.0 (when it is released)?
    >
    > Best regards
    > db

    Hi,

    I don't think it will ever be in FreeBSD, but I used ProPolice in the past:

    http://www.research.ibm.com/trl/projects/security/ssp/buildfreebsd.html

    The patch should be for 5.x in general, I don't use it anymore since some
    ports will break, if you play with it you can disable it by default and
    enable it explicit when you are willing to compile a binary with it.

    Once applied and compiled the whole base with it enabled, you cannot just
    turn back!

    Kind regards,
    Jimmy Scott

    ----------------------------------------------------------------
    This message has been sent through ihosting.be
    To report spamming or other unaccepted behavior
    by a iHosting customer, please send a message
    to abuse@ihosting.be
    ----------------------------------------------------------------
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Darren Reed: "Re: ipf stopped working on 5.3"

    Relevant Pages

    • Re: 2.6.0-test8-microcode
      ... patch and it will compile. ... The version of gcc that I am using didn't have ... Kind regards ...
      (Linux-Kernel)
    • RE: Can someone please help I have been stuck for days.
      ... I am 100% positive I am now running FC3. ... I followed your instructions by downloading ... the patch and the instructions for installing it. ... go into that file and chmod +x compile and run it. ...
      (Fedora)
    • Re: 2.6.25.X-rtX compile errors on ARM due to cmpxchg() problems.
      ... A while ago I already mentioned that 2.6.25 did not compile on ARM. ... Looking at the generic implementation I believe that this code should ... Revert the patch named arm-cmpxchg.patch in the preempt-rt patchset ...
      (Linux-Kernel)
    • Re: [REGRESSION] Recent change to kernel spikes out ccache/distcc
      ... How about this simple patch. ... It does cause ccache to be functional again, ... least as far as causing the "cache hit" stats to get bumped. ... how ccache misleadingly categorizes "cc -S" requests to compile to ...
      (Linux-Kernel)
    • Re: here is another oracle 10gs bug?
      ... N-Networks, makers of Dynamic PSP ... I'm sure I haven't exchange two plans. ... Also, I would recommend to patch your 10g to the latest patchset, ...
      (comp.databases.oracle.server)