Re: Buffer overflow prevention

From: Peter Busser (peter_at_trusteddebian.org)
Date: 08/15/03

  • Next message: Ricardo J. Ulisses Filho: "Re: PCL-0001: Remote Vulnerability in HORDE MTA < 2.2.4"
    Date: Fri, 15 Aug 2003 10:32:14 +0200
    To: bugtraq@securityfocus.com
    
    

    Hi!

    > >There is a flag for the Gnu C/C++ compilers, -fstack-protector, that will
    > >implement ProPolice stack protection. It should prevent stack smashing
    > >techniques.
    > >
    > That is not actually in the standard GCC; it is in a forked GCC that
    > OpenBSD chooses to ship.

    Adamantix and Gentoo Hardened also ship this patched GCC compiler.

    > We (Immunix) are in the process of trying to make StackGuard (the
    > original) meet all of the criteria required for acceptance into GCC. At
    > the GCC Summit <http://www.gccsummit.org/2003/> in May, we presented a
    > StackGuard talk
    > <http://www.gccsummit.org/2003/view_abstract.php?talk=31> on that topic.

    I would rather see Hiraoke Etoh's Stack Smashing Protector (aka ProPolice) as
    standard stack-smashing protection mechanism in GCC than StackGuard.

    Groetjes,
    Peter Busser

    -- 
    The Adamantix Project
    Taking trustworthy software out of the labs, and into the real world
    http://www.adamantix.org/
    

  • Next message: Ricardo J. Ulisses Filho: "Re: PCL-0001: Remote Vulnerability in HORDE MTA < 2.2.4"

    Relevant Pages

    • Re: [fbsd] Re: [fbsd] Integrating ProPolice/SSP into FreeBSD
      ... :>> that I want a nob for gcc to use the protection by default. ... Thus GCC would be merely SSP-ready for all applications. ... ports work without any pain, ... It is up to the user to manage with the SSP flags if he uses gmake ...
      (freebsd-current)
    • Re: Bye bye Keil 166 and 8051 (??)
      ... > One huge advantage to gcc is lack of copy protection. ... Have to pay the compiler vendor. ... N-week delay while you get a PO cut, ...
      (comp.arch.embedded)
    • Re: Integration of ProPolice in FreeBSD
      ... Luckily it seems that for now there is no function on the calling path ... stack-smashing protection. ... Does GCC provide an attribute that can be applied to a function to disable ... I should have mentionned that I've already skimmed over gcc info ...
      (freebsd-arch)
    • Re: [fbsd] Integrating ProPolice/SSP into FreeBSD
      ... nob for gcc to use the protection by default. ... so thanks for the clarification:) ...
      (freebsd-current)
    • Re: Which gcc is best?
      ... install a plain gcc system on my Mac that works the same way as any ... standard gcc on Linux? ... I don't think you'll ever get a Mac OS X GCC that behaves like Linux ...
      (comp.sys.mac.programmer.help)

  • Quantcast