Re: [Full-Disclosure] Talk in #grsecurity

Valdis.Kletnieks_at_vt.edu
Date: 03/27/04

  • Next message: Sean Crawford: "RE: [Full-Disclosure] People who ask support questions on FD"
    To: Henk Stubbe <henk@herejezus.nl>
    Date: Fri, 26 Mar 2004 18:44:37 -0500
    
    
    

    On Fri, 26 Mar 2004 23:10:02 +0100, Henk Stubbe <henk@herejezus.nl> said:

    > Spender sent me the alleged exploit for exec-shield... and it bypasses the
    > protections offered by exec-shield completely without the need for brute
    > forcing.

    Does it actually bypass a protection that exec-shield claims to give, or
    is it doing something that exec-shield doesn't claim to be able to stop?

    There's no love lost between the pax and exec-shield crews:

    http://marc.theaimsgroup.com/?l=linux-kernel&m=107209069402935&w=2
    http://marc.theaimsgroup.com/?l=linux-kernel&m=107209256604442&w=2

    So I'd evaluate very carefully any claim made by either crew. It's possible
    that there is a real hole in exec-shield. It's also possible that the
    "exploit" is simply doing stuff that exec-shield won't stop by design -
    remember that a design *goal* of exec-shield was to not be as kernel-intrusive
    as pax, so it would have a smaller footprint and be less likely to break stuff
    unintentionally.

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



  • Next message: Sean Crawford: "RE: [Full-Disclosure] People who ask support questions on FD"

    Relevant Pages

    • Re: [Full-Disclosure] Talk in #grsecurity
      ... > is it doing something that exec-shield doesn't claim to be able to stop? ... One of them was uncovered after a bug in PaXtest was fixed. ... > as pax, so it would have a smaller footprint and be less likely to break stuff ... And it can provide perfect protection against ALL attacks where ...
      (Full-Disclosure)
    • Re: thoughts on kernel security issues
      ... and it has different tradeoffs. ... major and two medium tradeoffs that PaX has, ... The technique exec-shield uses (to track the per-process 'highest ... If a 'generic' distribution (i.e. one that has a significant userbase, ...
      (Linux-Kernel)
    • Re: Linux Distribution Recomendation
      ... >> that his patch does everything that PaX does, without breaking compatibility. ... > In this one Ingo explicitly states a few times PaX is more secure than exec-shield. ... One important aspect is to assert that exec-shield is almost equal to PaX, ... The vision of the PaX author is that introducing and executing new ...
      (Security-Basics)
    • Re: thoughts on kernel security issues
      ... I think it's part of PaX. ... > PaX and Exec Shield both have them; personally I believe PaX is a more ... might this disagreement be based on the fact that exec-shield _is_ being ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)

    Loading