Re: Stack-Smash Protector

[email protected]
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
On Mon, 30 Sep 2002, Ivo Bitter wrote:

> On Mon, Sep 30, 2002 at 07:52:36PM +0100, Ian Molton wrote:
> > On Mon, 30 Sep 2002 03:54:59 +0000 (UTC)
> > [email protected] wrote:
> >
> > >
> > > POSIX compliance dictates that the stack should be executeable.  This
> > > is, of course, intensely obnoxious,
> >
> > Hadnt realised that. shocking.
> >
> > I wonder if its possible to disable that in the kernel. shouldnt be
> > hard, even if there is no option...
>
> The grsecurity patch (see www.grsecurity.net) has a non-executable
> stack option. I think the openwall patches have something similar for
> 2.2 kernels.

On bastion hosts I go with 2.2.x kernels for that very reason.  The
OpenWall patches have been through a LOT more testing and use than the
grsecurity patch for 2.4.x kernels.  OpenWall's patch used to be referred
to as the Solar Designer patch.  :)  It's been around a loooong time.

-- 
Unsubscribe: send email to [email protected]
and put 'unsubscribe lfs-security' in the subject header of the message
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.