Gentoo Archives: gentoo-hardened

From: Hinnerk van Bruinehsen <h.v.bruinehsen@×××××××××.de>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Tool for eliminating non used code or symbols?
Date: Tue, 26 Mar 2013 08:56:11
Message-Id: 20130326085444.GA3037@BIFROST.fritz.box
In Reply to: Re: [gentoo-hardened] Tool for eliminating non used code or symbols? by "Tóth Attila"
1 Normally you should have build nearly everything with PIE (there is a
2 nifty but a little bit outdated script called checksec.sh) - on my
3 system (Desktop with KDE right now) every running process has PIE
4 enabled.
5 You can enable and disable it via gcc-config (there are nopie and nopic
6 and vanilla compiler profiles (which seem to be incompatible with gcc 4.8) PIC and PIE enabled is the default though)
7
8 WKR
9 Hinnerk
10
11 On Mon, Mar 25, 2013 at 07:00:15PM +0100, "Tóth Attila" wrote:
12 > Is gentoo-hardened better regarding the amount of unrandomized code
13 > compared to other distros?
14 > --
15 > dr Tóth Attila, Radiológus, 06-20-825-8057
16 > Attila Toth MD, Radiologist, +36-20-825-8057
17 >
18 > 2013.Március 25.(H) 13:52 időpontban PaX Team ezt írta:
19 > > On 25 Mar 2013 at 9:01, Kfir Lavi wrote:
20 > >
21 > >> Hi,
22 > >> I'm looking for a way to reduce glibc code size.
23 > >> It can be a way to make system smaller and minimize the impact
24 > >> of attack vectors in glibc, as in return-to-libc attack.
25 > >
26 > > study this and draw your conclusions whether the whole exercise is
27 > > worth it or not:
28 > >
29 > > https://www.usenix.org/conference/usenix-security-11/q-exploit-hardening-made-easy
30 > >
31 > >
32 >
33 >
34 >

Attachments

File name MIME type
signature.asc application/pgp-signature