Gentoo Logo
Gentoo Spaceship

Installation:
Gentoo Handbook
Installation Docs

Documentation:
Home
Listing
About Gentoo
Philosophy
Social Contract

Resources:
Bug Tracker
Developer List
Discussion Forums
Gentoo BitTorrents
Gentoo Linux Enhancement Proposals
IRC Channels
Mailing Lists
Mirrors
Name and Logo Guidelines
Online Package Database
Security Announcements
Staffing Needs
Supporting Vendors
View our CVS

Graphics:
Logos and themes
Icons
ScreenShots

Miscellaneous Resources:
Gentoo Linux Store
Gentoo-hosted projects
IBM dW/Intel article archive




List Archive: gentoo-hardened
Navigation:
Lists: gentoo-hardened: < Prev By Thread Next > < Prev By Date Next >
Headers:
To: gentoo-hardened@g.o
From: Natanael Copa <natanael.copa@...>
Subject: Re: "How hard" is Linux kernel-side hardening?
Date: Mon, 21 Sep 2009 14:03:36 +0200
On Sat, 2009-09-19 at 22:25 +0200, Marco Venutti wrote:


> --[cut]--
>  You forgot to mention SSP (stack-smashing protection). 
> --[cut]--
> 
> I didn't forget it, but I'd like to primarily focus on 
> RSBAC and GR-Sec.

I think thats wrong focus. What makes grsecurity (and gentoo hardened)
interesting is PaX, not the RSBAC. Same is to be said about the
corresponding functionallity in OpenBSD.

Vanilla kernel (and SElinux etc) don't have PaX.

I can recommend you to read up on what PaX does for you. Basicly, PaX
prevent you to exploit vulnerabilities. selinux will only limit what
your successful exploit is allowed to do.

My biggest worries when it comes to PaX (for the moment) is that you
cannot run paravirtualization with PaX.

-nc



Replies:
Re: "How hard" is Linux kernel-side hardening?
-- Marco Venutti
References:
"How hard" is Linux kernel-side hardening?
-- Marco Venutti
Re: "How hard" is Linux kernel-side hardening?
-- atoth
Re: "How hard" is Linux kernel-side hardening?
-- Marco Venutti
Navigation:
Lists: gentoo-hardened: < Prev By Thread Next > < Prev By Date Next >
Previous by thread:
Re: "How hard" is Linux kernel-side hardening?
Next by thread:
Re: "How hard" is Linux kernel-side hardening?
Previous by date:
Re: "How hard" is Linux kernel-side hardening?
Next by date:
Re: "How hard" is Linux kernel-side hardening?


Updated Nov 22, 2009

Donate to support our development efforts.

Gentoo Centric Hosting: vr.org

VR Hosted

Tek Alchemy

Tek Alchemy

SevenL.net

SevenL.net

php|architect

php|architect

Copyright 2001-2007 Gentoo Foundation, Inc. Questions, Comments? Email www@gentoo.org.