Re: SLFS book chapter proposals

DJ Lucas <[email protected]>
Newsgroups gmane.linux.lfs.security
Organization Linux From Scratch
Message-ID <[email protected]>
Bill's LFS Login wrote:

> 
> IIRC, examples are shown and publicly available on sites dedicated to
> security. I don't have the URLs availabe ATM, but they could be included
> in the book to provide that info. IIRC, one of the standard procedures
> on these sites requires proof of the weakness, including code that
> exploits the vulnerability.
> 

Links are just fine...no need to copy verbatim what is already availible.

In a previous post Christos Gioran wrote:

> Show him/her how to compile a program with 
> an unpatched gcc (probably the one of the host system's) and demostrate a 
> simple buffer overflow. Then do the same thing with the patched gcc. Voila, 
> in front of his/her eyes the system is more secure.
> 

Then I wrote in reply:

>>I personally would like to see this for each type of exploit mentioned
>>in the fundamental knowledge chapter.  Someone had mentioned in another
>>thread that this might be a 'hacker's howto' of sorts.  This seems
>>dangerous, but at the same time, how can you fix a vulnerability if you
>>don't understand how the exploit works in the first place?
> 
> 

Referencing my own statement above...

Again, no need to duplicate documentation if the links point to and show 
the vulnerability in detail.  I just don't know where to find that 
information.  Links fit well with what I was trying to suggest, so long 
as the book can add to what is already there in the interest of teaching.

-- DJ

-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.