Re: Unexecutable Stack / Buffer Overflow Exploits...

Horst von Brand (vonbrand@sleipnir.valparaiso.cl)
Mon, 3 Jan 2000 02:45:13 +0200


Gregory Maxwell <greg@linuxpower.cx> said:
> On Thu, 30 Dec 1999, Horst von Brand wrote:
> [snip]
> > Get the patch and apply it. I prefer not to rely on papering over the
> > holes.

[...]

> Seriously, no one here would dare replace a real fix with a stack
> paperbag.

OK.

[...]

> With the advent of scripted identifying and autorooting, it's possible for
> an attacker to root dozens, if not hunderds, of systems within hours of an
> exploit release.

Note that they _don't_ write this themselves, they get them prepackaged
from somewhere. So the next epidemy includes identifying nonexec-stack
machines, and has specific exploits for them. You gained nothing in the
long run, everybody lost. Sure, it may make you somewhat safer now. So
apply the patches.

> So even if I had my beeper connected to bugtrack and every underground
> cracker IRC channel, I could still be rooted before I got to the keyboard.

Nonexecutable stack won't change that a bit.

-- 
Horst von Brand                             vonbrand@sleipnir.valparaiso.cl
Casilla 9G, Viņa del Mar, Chile                               +56 32 672616

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu Please read the FAQ at http://www.tux.org/lkml/