* [patch] updated exec-shield patch, 2.4/2.6 -G3
@ 2003-09-26 12:28 Ingo Molnar
2003-09-26 17:13 ` Valdis.Kletnieks
0 siblings, 1 reply; 3+ messages in thread
From: Ingo Molnar @ 2003-09-26 12:28 UTC (permalink / raw)
To: linux-kernel
in the recent boom of buffer-overflow bugs in various open-source packages
i got lots of requests for exec-shield being ported to various popular
kernel trees. Here's the latest update of exec-shield:
against vanilla 2.6.0-test5:
redhat.com/~mingo/exec-shield/exec-shield-2.6.0-test5-G2
against vanilla 2.4.22:
redhat.com/~mingo/exec-shield/exec-shield-2.4.22-G2
against 2.4.22-ac + NPTL:
[ redhat.com/~mingo/nptl-patches/nptl-2.4.22-ac1-A2 ]
redhat.com/~mingo/exec-shield/exec-shield-2.4.22-ac1-nptl-G2
Changes in this exec-shield version:
- more refined support for PIE binaries (Position Independent Executables
- a feature of latest binutils)
- complete randomization of the whole address space [except the static
binary mappings for non-PIE binaries]. Randomized executable mappings,
heap, data mappings, stack, env/argv/aux spaces. With PIE binaries
there's not a single constant address left.
- ability to turn off exec-shield without changing the binary.
(try 'setarch i386 /bin/cat /proc/self/maps'.)
- various compatibility features and fixes.
- randomization can be turned off via /proc/sys/kernel/exec-shield-randomize.
valid /proc/sys/kernel/exec-shield levels are:
= 0 exec-shield disabled
= 1 exec-shield on PT_GNU_STACK executables [ie. binaries compiled
with newest gcc]
= 2 (default) exec-shield on all executables
value 1 is recommended with glibc and gcc versions that support
PT_GNU_STACK all across the spectrum. (Fedora Core test2 [released
yesterday] includes all of this and all applications were recompiled to
have valid PT_GNU_STACK settings.) On other systems the value of '2' is
recommended, use setarch for those binaries that cannot take exec-shield
[eg. Loki games].
reports, comments welcome. Enjoy it,
Ingo
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [patch] updated exec-shield patch, 2.4/2.6 -G3
2003-09-26 12:28 [patch] updated exec-shield patch, 2.4/2.6 -G3 Ingo Molnar
@ 2003-09-26 17:13 ` Valdis.Kletnieks
2003-09-26 17:24 ` Ingo Molnar
0 siblings, 1 reply; 3+ messages in thread
From: Valdis.Kletnieks @ 2003-09-26 17:13 UTC (permalink / raw)
To: Ingo Molnar; +Cc: linux-kernel
[-- Attachment #1: Type: text/plain, Size: 1553 bytes --]
On Fri, 26 Sep 2003 14:28:54 +0200, Ingo Molnar <mingo@elte.hu> said:
> against vanilla 2.6.0-test5:
>
> redhat.com/~mingo/exec-shield/exec-shield-2.6.0-test5-G2
Ingo, you rock. ;) I'm using a fairly current Rawhide here (within last 2
weeks or so).
Applied with 2 or 3 minor conflicts and a few fuzz/delta messages against
-test5-mm4 (I have a refactored patch if anybody is interested). It booted
OK, seems to be working well enough that e-mail and XFree (even with the
evil binary NVidia driver) are functional.
> = 0 exec-shield disabled
> = 1 exec-shield on PT_GNU_STACK executables [ie. binaries compiled
> with newest gcc]
> = 2 (default) exec-shield on all executables
>
> value 1 is recommended with glibc and gcc versions that support
> PT_GNU_STACK all across the spectrum. (Fedora Core test2 [released
> yesterday] includes all of this and all applications were recompiled to
> have valid PT_GNU_STACK settings.) On other systems the value of '2' is
> recommended, use setarch for those binaries that cannot take exec-shield
> [eg. Loki games].
I'm assuming it's this GCC change in Rawhide:
* Wed Jun 04 2003 Jakub Jelinek <jakub@redhat.com> 3.3-4
- mark object files with .note.GNU-stack notes whether they
need or don't need executable stack
(and another at 3.3-5). Has the current Rawhide been recompiled with this
support, or should I stick with '2' and use setarch for things that fail?
Now to go build a testcase program and try to shellcode it. ;)
[-- Attachment #2: Type: application/pgp-signature, Size: 226 bytes --]
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [patch] updated exec-shield patch, 2.4/2.6 -G3
2003-09-26 17:13 ` Valdis.Kletnieks
@ 2003-09-26 17:24 ` Ingo Molnar
0 siblings, 0 replies; 3+ messages in thread
From: Ingo Molnar @ 2003-09-26 17:24 UTC (permalink / raw)
To: Valdis.Kletnieks; +Cc: linux-kernel
On Fri, 26 Sep 2003 Valdis.Kletnieks@vt.edu wrote:
> On Fri, 26 Sep 2003 14:28:54 +0200, Ingo Molnar <mingo@elte.hu> said:
>
> > against vanilla 2.6.0-test5:
> >
> > redhat.com/~mingo/exec-shield/exec-shield-2.6.0-test5-G2
>
> Ingo, you rock. ;) I'm using a fairly current Rawhide here (within last 2
> weeks or so).
>
> Applied with 2 or 3 minor conflicts and a few fuzz/delta messages
> against -test5-mm4 (I have a refactored patch if anybody is interested).
> It booted OK, seems to be working well enough that e-mail and XFree
> (even with the evil binary NVidia driver) are functional.
btw., i have a patch against Linus' latest, -bk12 too:
redhat.com/~mingo/exec-shield/exec-shield-2.6.0-test5-bk12-G2
> I'm assuming it's this GCC change in Rawhide:
>
> * Wed Jun 04 2003 Jakub Jelinek <jakub@redhat.com> 3.3-4
>
> - mark object files with .note.GNU-stack notes whether they
> need or don't need executable stack
yes. The kernel ELF loader now detects this PT_GNU_STACK program header
entry and acts upon it. (when using the setting of 1.)
> (and another at 3.3-5). Has the current Rawhide been recompiled with this
> support, or should I stick with '2' and use setarch for things that fail?
it's quit easy to check: with a setting of 1, does 'cat /proc/self/maps'
show a randomized layout, while 'setarch i386 cat /proc/self/maps' shows a
regular layout? If /bin/cat defaults to exec-shield even with a setting of
1 then everything's recompiled.
in fact with glibc-2.3.2-92 and later ld.so will revert a non-executable
stack to executable if a binary loads a DSO that needs an executable
stack. 'tuxracer' is one such very important example :-)
> Now to go build a testcase program and try to shellcode it. ;)
i see the smiley - but it would truly be interesting to try to find the
boundaries of exec-shield and try to exploit it.
Ingo
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2003-09-26 17:26 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2003-09-26 12:28 [patch] updated exec-shield patch, 2.4/2.6 -G3 Ingo Molnar
2003-09-26 17:13 ` Valdis.Kletnieks
2003-09-26 17:24 ` Ingo Molnar
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®