Gentoo Archives: gentoo-hardened

From: atoth@××××××××××.hu
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Keeping gentoo-hardened alive (WAS: latest kernel exploit patch for vmsplice coming?)
Date: Fri, 15 Feb 2008 05:55:39
Message-Id: 33356.138.26.140.45.1203054931.squirrel@atoth.sote.hu
In Reply to: Re: [gentoo-hardened] Keeping gentoo-hardened alive (WAS: latest kernel exploit patch for vmsplice coming?) by Geoff Kassel
1 On Pén, Február 15, 2008 05:14, Geoff Kassel wrote:
2 > Hmm... I didn't know that you could restore a process fully from a core
3 > dump -
4 > hence the question. (My ignorance is showing again :) How interesting. In
5 > that case, there is no difference between the process image serialisation
6 > and
7 > the coredump, so I'm sorry for wasting your time on that hypothetical.
8
9 Called post-mortem analysis. No tricks, just gdb.
10
11 >
12 > Is such a real-time removal of protections possible with the way PaX is
13 > currently implemented? If not, I think it'd be an interesting feature in
14 > the
15 > eventuality of such a process suspension feature being developed.
16
17 Please take a look at paxctl (there's an ebuild for it). MPROTECT can be
18 also fine-tuned on a per-process basis. The mechanism is not real-time,
19 the changes should be applied before running. However the settings are
20 preserved.
21
22 Regards,
23 Dw.
24
25 --
26 dr Tóth Attila, Radiológus Szakorvos jelölt, 06-20-825-8057, 06-30-5962-962
27 Attila Toth MD, Radiologist in Training, +36-20-825-8057, +36-30-5962-962
28
29 --
30 gentoo-hardened@l.g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] Keeping gentoo-hardened alive (WAS: latest kernel exploit patch for vmsplice coming?) Geoff Kassel <gkassel@×××××××××××××××××.net>