Re: [Full-Disclosure] "Advances in Security" in the Linux Kernel and RedHat idiocy

From: Arjan van de Ven (arjanv_at_redhat.com)
Date: 01/27/05

  • Next message: Jeremy Davis: "Re: [Full-Disclosure] spoolcll.exe - new worm being distributed viamysql vulnerability?"
    Date: Thu, 27 Jan 2005 18:28:12 +0100
    To: Brad Spengler <spender@grsecurity.net>
    
    

    On Thu, Jan 27, 2005 at 11:10:43AM -0500, Brad Spengler wrote:
    > Just wanted to point out to you guys the INCREDIBLE advances in Linux
    > security underway on LKML from security expert Arjan van de Ven:
    >
    > http://lkml.org/lkml/2005/1/27/62
    >
    > On the subject of his i386-only mmap randomization patch:
    >
    > The randomisation range is 1 megabyte (this is bigger than the stack
    > randomisation since the stack randomisation only needs 16 bytes alignment
    > while the mmap needs page alignment, a 64kb range would not have given
    > enough entropy to be effective)
    >
    > If we do a little math..
    > 1048576 / 4096 = 256
    > 65536 / 16 = 4096
    >
    > 256 different locations for the mmap base, 4096 different locations for
    > the stack (and apparently argv/envp pages get no randomization)
    >
    > Anyone with half a brain would see this is a joke, but not security
    > expert Arjan van de Ven:

    I think the joke is on you in this case. There is a large patch series of
    which you judge the first steps only. Those steps introduce the
    infrastructure and concepts into the kernel, and later patches will tweak
    the exact numbers to values with more entropy. ONCE THEY EXISTING
    INFRASTRUCTURE IS ACCEPTED AND DEBUGGED.

    Maybe you don't understand that, I assume a lot of the other readers of this
    list do. You don't plop a huge patch in the linux kernel in one chunk. You
    do it in nice small, incremental and debuggable steps.

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Jeremy Davis: "Re: [Full-Disclosure] spoolcll.exe - new worm being distributed viamysql vulnerability?"

    Relevant Pages

    • RE: [Full-Disclosure] Re: January 15 is Personal Firewall Day, he lp the cause
      ... supply of patches (Windows NT4/95/98) these systems should go offline ... Security is always a trade-off. ... This is how Linux and other ... Apache virtually owns the market with more than 60%. ...
      (Full-Disclosure)
    • SecurityFocus Linux Newsletter #39
      ... Subject: SecurityFocus Linux Newsletter #39 ... Need to keep track of the latest vulnerability information? ... vulnerabilities for both security product vendors and corporate security ... NEW PRODUCTS FOR LINUX PLATFORMS ...
      (Focus-Linux)
    • RE: Linux hacked
      ... Subject: Linux hacked ... After you boot up into the OS running from CD, ... >> First let me say I'm a security novice. ... >> been unsuccessful in getting root back. ...
      (Security-Basics)
    • Re: Community responsibility and abuse (2): the case of top-
      ... Without ANY evidence of ANY security problems you try ... PLEASE PROVIDE EVIDENCE OF ANY ... evidence that Linux is anywhere near as insecure as windows. ... Still no "spacific evidence that Linux is anywhere near as insecure as ...
      (alt.linux)
    • Re: testing laptop based on bsd anyone
      ... "A new linux distribution for Wardrivers" ... I wasn't speaking about the relative strengths of security measures within ... As attacks through web applications continue to rise, ... vulnerability management needs. ...
      (Pen-Test)