|
From: Heiko Z. <he...@zu...> - 2003-08-04 23:30:23
|
Dean Nedelman wrote: >>>On 08/04/2003 05:02:37 PM Manu wrote: >>> >>>>Heiko Zuerker a écrit: >>>> >>>>Hey guys, >>>> >>>>I successfully intregrated the GCC stack smashing protector into DL ! >>>>For more information about this >>> >>>piece:http://www.research.ibm.com/trl/projects/security/ssp >>> >>>Great feature it is; now, if I understand well, one have to enable >>>fstack-protector in each compile script and see if it works well ?? >> >>Not really. It's enabled by default and you have to disable it for each >>application which doesn't work anymore. ;-) >>I had to do this for the kernel (build/scripts/linux) and some other >>modules, but there can still be some apps out there which have problems >>once you try to run them. >> >>Heiko > > > ...i think i better stock up on CD's, because I sense that this is going to > take a few builds... :-) > > Seriously, I thought that the PAX part of GRSecurity did this. Do we now > have TWO stack smashing protectors, or was the PAX one disabled? We didn't use the PAX patch for GCC. I didn't like it when I took a look at it, but can't remember what I didn't like. So far it looks good, the CD bootet without any problems on my test server. Heiko |