1 |
Nitin Kanaskar <nitinvk04 <at> gmail.com> writes: |
2 |
|
3 |
|
4 |
> Thank you so much Dale again - but i |
5 |
> would try to follow links given by Neil - |
6 |
> thank you Neil - and chk in the cvs repositories. |
7 |
> Really appreciate your willingness to help. |
8 |
|
9 |
Hello Nitin, |
10 |
|
11 |
After reading your thread, you seem to be a bit |
12 |
flexible in what you pursue as opportunities |
13 |
for security analysis. Just a suggestion, but, |
14 |
in lieu of pursuing a very 'well worn path' of |
15 |
vulnerability assessments, might you be interested |
16 |
in exploring an alternative? |
17 |
|
18 |
|
19 |
If so, consider testing for security vulnerabilities |
20 |
on a variety of embedded (Gentoo) linux devices/architectures? |
21 |
|
22 |
|
23 |
You'll find embedded linux on a variety of hardware, |
24 |
very rich in opportunities for exploits. There are |
25 |
far fewer folks to test and fix problems, and many |
26 |
of the builds are barely able to support the |
27 |
arch, let alone robust security analysis. You |
28 |
could easily distinguish your self and provide a |
29 |
huge service to the gentoo community, not to mention |
30 |
working with some very sharp minds who |
31 |
inhabit this space. |
32 |
|
33 |
|
34 |
For example, you could test the vulnerability |
35 |
difference between the various C libraries, |
36 |
with all else being the same. Or look at vulnerability |
37 |
differences between soft-float and using builds |
38 |
based on hardware, just to name a few. Certainly with |
39 |
a quick survey of the space, you can come up |
40 |
with lots of ideas that would yield lots of |
41 |
uniquely interesting information, and blaze a new path. |
42 |
Gentoo on ARM is a HUGE opportunity for distinction. |
43 |
|
44 |
|
45 |
Here are a few links for your perusal: |
46 |
|
47 |
http://www.gentoo.org/proj/en/base/embedded/index.xml |
48 |
|
49 |
http://www.gentoo.org/proj/en/base/embedded/handbook/ |
50 |
|
51 |
http://tinderbox.dev.gentoo.org/ |
52 |
|
53 |
http://slonopotamus.org/gentoo-on-n8x0 |
54 |
|
55 |
http://en.gentoo-wiki.com/wiki/TinyGentoo |
56 |
|
57 |
http://wiki.debian.org/ArmEabiPort |
58 |
|
59 |
http://www.codesourcery.com/sgpp/lite/arm/portal/target_arch1?@template=faq#q_gnu_linux_long_long |
60 |
|
61 |
http://martinwguy.co.uk/martin/tech/Maverick/ |
62 |
|
63 |
Just a suggestion.... |
64 |
|
65 |
hth, |
66 |
James |