Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
A Security Wish List for 2002
Jon Lasser, 2002-01-09

An end to buffer overflows, and a beginning to serious user education ... These are a few of my favorite things.

Comments Mode:
A Security Wish List for 2002 2002-01-09
Anonymous (5 replies)
A Security Wish List for 2002 2002-01-09
Anonymous
A Security Wish List for 2002 2002-01-10
Anonymous (2 replies)
Languages can be fast _and_ safe 2002-01-10
Anonymous
Java Performance 2002-01-10
Anonymous (1 replies)
Java Performance (and app performance in general) 2002-01-26
The Shadow Knows . . .
A Security Wish List for 2002 2002-01-10
Anonymous
A Security Wish List for 2002 2002-01-11
Anonymous (1 replies)
Java vs Python 2002-01-20
Anonymous
A Security Wish List for 2002 2002-01-24
Amarendra GODBOLE [amar AT efn DOT org]
A Security Wish List for 2002 2002-01-10
Anonymous
A Security Wish List for 2002 2002-01-10
Anonymous (1 replies)
learn asm? dumb idea. 2002-01-14
player 2 (1 replies)
learn asm? dumb idea. 2002-01-20
Levi (2 replies)
stupid idea... 2002-01-30
Anonymous
learn asm? dumb idea. 2002-01-30
retro
Security Education 2002-01-10
Educator (5 replies)
Security Education 2002-01-11
Anonymous
Security Education 2002-01-14
Anonymous
Security Education 2002-01-19
Anonymous
Security Education 2002-01-19
Anonymous
A Security Wish List for 2002: the stack 2002-01-10
scott@surfprivately.com
A kernel stack protection patch based on SD's was available on www.getrewted.net several months ago, you can find variants of it on several sites, e.g. at www.conostix.org/~fpmip/secos-patch/. There are also rpms of the libsafe library available if one has a hard time with kernel patches. Daemons which are often attacked are good targets for StackGuard compiles, which I did on my systems ages ago, also replacing the wu/proftpd usually found with the OpenBSD one.

Sure, it'd be nice for all these things to be done for us in the distributions. Mandrake includes libsafe by default now, I think. But aren't things like this what we get paid for anyway? After using stack protection in Solaris 2.6, I haven't installed a system without it. Why wait for the vendors? Do it yourself! :-)

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/52/9779#9779
We all have same urge to amend reality 2002-01-10
by law or action or by dreaming our way around it...
A Security Wish List for 2002 2002-01-10
Night Hawk
A Security Wish List for 2002 2002-01-12
Elc0chin0
A Security Wish List for 2002 2002-01-24
Amarendra GODBOLE [amar AT efn DOT org ]
A Security Wish List for 2002 2002-01-28
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus