SLFS book chapter proposals

Christos Gioran <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
Good evening(day, whatever) all,
	Just to get the discussion around this going....

One chapter should deal with fundamental knowledge, such as what buffer 
overflows are, basics on format string vulnerabilities etc. Thus the reader 
realises the threats that exist and the need to deal with them

Another could explain the purpose of every package installed in addition to 
the standard LFS. Thus, if the reader has understood the build procedure of 
the LFS, he/she should also come closer to the solutions presented in the 
book. Why do we install propolice? Show him/her how to compile a program with 
an unpatched gcc (probably the one of the host system's) and demostrate a 
simple buffer overflow. Then do the same thing with the patched gcc. Voila, 
in front of his/her eyes the system is more secure.

Explanation of the build procedure should follow. The (probably different in 
comparison to LFS) build order, explanation for it in detail so the reader 
understands every step. Also, here there could be shortcuts that can be 
taken, pointers for deviations from the book etc. The "how things are going 
to be done" section.

Downlads: These packages, these patches. Optionally these and these.

Build instructions. Fully detailed steps, explained but no duplication of 
information from previous sections. It should be supposed that the reader has 
reached this part of the book aware of what is going to be done and simply 
wants guidance. Here, the knowledge passed should be highly concentrated.

Somewhere there should be a disclaimer, stating the "your responcibility" 
culture of GNU and also a paragraph or two saying what the whole project is 
about ("we are trying to make sure that a system is build from source and it 
is implemented with low-level countermeasures against standard exploitation 
tecniques....")

Just some pointers. Let's get the structure hassle out of the way, don't you 
think?

himicos
-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.