Re: SLFS book chapter proposals
Bill's LFS Login <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
On Fri, 19 Dec 2003, DJ Lucas wrote: > Christos Gioran wrote: > > Good evening(day, whatever) all, > > Just to get the discussion around this going.... > > Hello, as a security clueless user who's been silently listening in the > background,[...] > > One chapter should deal with fundamental knowledge, such as what buffer > > overflows are, basics on format string vulnerabilities etc. Thus the reader > > realises the threats that exist and the need to deal with them > > > > I dont' know exactly how feasible it would be to show common examples of > code that lead to the vulnerabilities mentioned in that chapter, but > it'd be nice to see exactly what to look for in the code to find these > vulnerabilities, also what not to do when writing your own programs. IIRC, examples are shown and publicly available on sites dedicated to security. I don't have the URLs availabe ATM, but they could be included in the book to provide that info. IIRC, one of the standard procedures on these sites requires proof of the weakness, including code that exploits the vulnerability. > > > Another could explain the purpose of every package installed in addition to > > the standard LFS. Thus, if the reader has understood the build procedure of > > the LFS, he/she should also come closer to the solutions presented in the > > book. Why do we install propolice? Show him/her how to compile a program with > > an unpatched gcc (probably the one of the host system's) and demostrate a > > simple buffer overflow. Then do the same thing with the patched gcc. Voila, > > in front of his/her eyes the system is more secure. > > > > I personally would like to see this for each type of exploit mentioned > in the fundamental knowledge chapter. Someone had mentioned in another > thread that this might be a 'hacker's howto' of sorts. This seems > dangerous, but at the same time, how can you fix a vulnerability if you > don't understand how the exploit works in the first place? If the code samples I mentioned above really do exist, there is no increase in risk, just maybe a wider distribution if the book points to those items. > <snip> > -- DJ -- NOTE: I'm on a new ISP, if I'm in your address book ... Bill Maltby lfsbillATearthlinkDOTnet Fix line above & use it to mail me direct. -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page