On Thu, 2005-12-08 at 17:08, linux-os (Dick Johnson) wrote: > An 8 megabyte variation is absolutely insane. It follows the "If a > little is good, more must be better..." theory. The purpose of > the random stack start, initially proposed by me BTW, was to > prevent stack-exploit code from being able to hard-code addresses > on the stack. Being off by one byte is enough, 8192 was originally > discussed and, I thought, adopted. Eight megabytes is absurd and has > no technical basis. If you only randomize by one or two bytes, the attacker just has to retry once or twice to have his exploit work. Even once in 1024 may be too much for some security-conscious people. The larger the area (with a fixed step), the less statistically efficient the rootkit. Xav - To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to [email protected] More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
- Follow-Ups:
- Re: How to enable/disable security features on mmap() ?
- From: Arjan van de Ven <[email protected]>
- Re: How to enable/disable security features on mmap() ?
- References:
- How to enable/disable security features on mmap() ?
- From: Emmanuel Fleury <[email protected]>
- Re: How to enable/disable security features on mmap() ?
- From: Arjan van de Ven <[email protected]>
- Re: How to enable/disable security features on mmap() ?
- From: Emmanuel Fleury <[email protected]>
- Re: How to enable/disable security features on mmap() ?
- From: Emmanuel Fleury <[email protected]>
- Re: How to enable/disable security features on mmap() ?
- From: Arjan van de Ven <[email protected]>
- Re: How to enable/disable security features on mmap() ?
- From: Emmanuel Fleury <[email protected]>
- Re: How to enable/disable security features on mmap() ?
- From: "linux-os \(Dick Johnson\)" <[email protected]>
- Re: How to enable/disable security features on mmap() ?
- From: Arjan van de Ven <[email protected]>
- Re: How to enable/disable security features on mmap() ?
- From: "linux-os \(Dick Johnson\)" <[email protected]>
- How to enable/disable security features on mmap() ?
- Prev by Date: Re: Problem with using spinlocks when kernel is compiled withoutsmp-support
- Next by Date: Re: How to enable/disable security features on mmap() ?
- Previous by thread: Re: How to enable/disable security features on mmap() ?
- Next by thread: Re: How to enable/disable security features on mmap() ?
- Index(es):