Gentoo Archives: gentoo-security

From: Daniel Brandt <daniel.brandt@××××.se>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] Built in integrity?
Date: Tue, 10 Feb 2004 13:17:14
Message-Id: 20040210141533.6bd839d7.daniel.brandt@home.se
In Reply to: Re: [gentoo-security] Built in integrity? by Daniel Heemann
1 > <..> Normally on a system which needs to be secure you don't
2 > have any compiler <..>
3
4 Oh no.. Not this again.
5
6 Having a compiler on the system _does NOT matter_!
7
8 What? You think it's bad if an attacker can compile stuff on your server? If you know you won't find an attacker _before_ he's playing with your compiler you should be more worried about your perimeter.
9
10 If I put myself in the attackers perspective, I would never compile exploit source code on a cracked server. I would use obfuscated binaries, nothing else, as this would further lessen the odds of discovery.
11
12 Doesn't OpenBSD ship with a compiler? It does. Applying patches to source code and compiling it is even the recommended way of keeping your system up to date.
13
14 A compiler is not a security risk.
15
16 // Daniel
17
18 --
19 gentoo-security@g.o mailing list

Replies

Subject Author
Re: [gentoo-security] Built in integrity? Matt Steven <matt@×××××××××.com>
Re: [gentoo-security] Built in integrity? Daniel Heemann <daniel.heemann@×××.de>