Re: SLFS book chapter proposals

Bill's LFS Login <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
On Fri, 19 Dec 2003, DJ Lucas wrote:

> Christos Gioran wrote:
> > Good evening(day, whatever) all,
> > 	Just to get the discussion around this going....
>
> Hello, as a security clueless user who's been silently listening in the
> background,[...]

> > One chapter should deal with fundamental knowledge, such as what buffer
> > overflows are, basics on format string vulnerabilities etc. Thus the reader
> > realises the threats that exist and the need to deal with them
> >
>
> I dont' know exactly how feasible it would be to show common examples of
> code that lead to the vulnerabilities mentioned in that chapter, but
> it'd be nice to see exactly what to look for in the code to find these
> vulnerabilities, also what not to do when writing your own programs.

IIRC, examples are shown and publicly available on sites dedicated to
security. I don't have the URLs availabe ATM, but they could be included
in the book to provide that info. IIRC, one of the standard procedures
on these sites requires proof of the weakness, including code that
exploits the vulnerability.

>
> > Another could explain the purpose of every package installed in addition to
> > the standard LFS. Thus, if the reader has understood the build procedure of
> > the LFS, he/she should also come closer to the solutions presented in the
> > book. Why do we install propolice? Show him/her how to compile a program with
> > an unpatched gcc (probably the one of the host system's) and demostrate a
> > simple buffer overflow. Then do the same thing with the patched gcc. Voila,
> > in front of his/her eyes the system is more secure.
> >
>
> I personally would like to see this for each type of exploit mentioned
> in the fundamental knowledge chapter.  Someone had mentioned in another
> thread that this might be a 'hacker's howto' of sorts.  This seems
> dangerous, but at the same time, how can you fix a vulnerability if you
> don't understand how the exploit works in the first place?

If the code samples I mentioned above really do exist, there is no
increase in risk, just maybe a wider distribution if the book points to
those items.

> <snip>

> -- DJ

-- 
NOTE: I'm on a new ISP, if I'm in your address book ...
Bill Maltby
lfsbillATearthlinkDOTnet
Fix line above & use it to mail me direct.
-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.