Re: [Announcement] "Exec Shield", new Linux security feature

Sean Neakums (sneakums@zork.net)
Sun, 04 May 2003 16:48:08 +0100


"Calin A. Culianu" <calin@ajvar.org> writes:

> On Sun, 4 May 2003, Ingo Molnar wrote:
>>
>> wrt. address-space randomization, "prelink -R" already provides quite good
>> randomization of the shared library addresses, which should give some
>> statistical protection against remote attacks, i dont think we'll need
>> kernel support for that.
>
> What is prelink -R?

-R --random
When assigning addresses to libraries, start with random
address within architecture dependant virtual address
space range. This can make some buffer overflow attacks
slightly harder to exploit, because libraries are not
present on the same addresses accross different
machines. Normally, assigning virtual addresses starts
at the bottom of architecture dependant range.

-- 
Sean Neakums - <sneakums@zork.net>
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/