BugTraq
Re: Buffer overflow prevention Aug 14 2003 05:26PM
Mariusz Woloszyn (emsi ipartners pl) (6 replies)
Re: Buffer overflow prevention Aug 14 2003 11:27PM
Shaun Clowes (shaun securereality com au) (1 replies)
Re: Buffer overflow prevention Aug 15 2003 06:48PM
Crispin Cowan (crispin immunix com) (1 replies)
Re: Buffer overflow prevention Aug 17 2003 11:09PM
Shaun Clowes (shaun securereality com au) (1 replies)
On Fri, Aug 15, 2003 at 11:48:14AM -0700, Crispin Cowan wrote:
> Shaun Clowes wrote:
>
> >Perhaps I'm the only one who feels this way, but I believe that the vast
> >majority of the exploitation of systems is being performed by people
> >with no knowledge of how to write an exploit and that the vast majority
> >of exploits are fragile. Doing anything that makes you different from
> >every other installation of Linux/HPUX/Solaris/InsertOSHere will
> >drastically decrease the changes of any point and click exploit working
> >against you.
> >
> >Could a determined (and knowledgable) attacker still get through? Sure.
> >But if we're talking protections that take very little effort to
> >implement, have a minor performance impact and will save your
> >skin some of the time, it's obvious that it's worth deploying them. As
> >long as you're not kidding yourself that you're then totally secure.
> >
> Exactly: trivial changes will protect you from script kiddies.
> Non-bypassability is required to protect you from determined attackers.
> It depends on your threat model: how much will a penetration event cost
> you? What is it worth to someone to hack you?

Well, you've immediately eliminated 90% or more of the threat, so it's a
good start. In any case, if we are talking about the famous determined
attacker it's reasonable to assume that they are going to get you no
matter what you do and that you need to carefully consider methods of
reducing the damage from intrusion (rather than betting on stopping the
intrusion all together).

> >Its kind of reminiscent of that old joke about the two guys running away
> >from the lion. You don't have to beat the lion, just the other person.
> >
> But if you taste better (you are a bank and he is a basement RH box)
> then the lion may choose to chase you anyway.

If I'm the bank I'm probably running Solaris, HP-UX, AIX, Irix etc, in
which case I don't even have the option of PaX etc. I would deploy any
kind of protection technology I could find (including non-executable
stack, moved library images etc).

There is no such thing as a perfect protection, and most of the
protection technologies that have been discussed in this thread are
worth considering. It would seem most pragmatic to deploy whatever you
can in your environment.

I think it's generally accepted that homogenity breeds insecurity, in
which case it makes sense to try to be as different from everyone else
as possible even if that doesn't make it impossible for someone to break
you.

Cheers,
Shaun

[ reply ]
Re: Buffer overflow prevention Aug 17 2003 10:42PM
Crispin Cowan (crispin immunix com) (2 replies)
Heterogeneity as a form of obscurity, and its usefulness Aug 21 2003 02:00AM
Bob Rogers (rogers-bt2 rgrjr dyndns org) (1 replies)
Re: Heterogeneity as a form of obscurity, and its usefulness Aug 22 2003 03:56AM
Crispin Cowan (crispin immunix com) (1 replies)
Re: Heterogeneity as a form of obscurity, and its usefulness Aug 22 2003 06:21PM
Nicholas Weaver (nweaver CS berkeley edu)
Re: Buffer overflow prevention Aug 18 2003 06:07PM
Mark Handley (M Handley cs ucl ac uk) (1 replies)
Re: Buffer overflow prevention Aug 18 2003 08:11PM
Crispin Cowan (crispin immunix com)
Re: Buffer overflow prevention Aug 14 2003 07:37PM
Theo de Raadt (deraadt cvs openbsd org) (3 replies)
Re: Buffer overflow prevention Aug 16 2003 01:14PM
sauron (unixlabs noos fr)
Re: Buffer overflow prevention Aug 14 2003 09:14PM
Gerhard Strangar (gerhard brue net) (1 replies)
Re: Buffer overflow prevention Aug 14 2003 09:43PM
Theo de Raadt (deraadt cvs openbsd org) (1 replies)
Re: Buffer overflow prevention Aug 14 2003 10:19PM
Gerhard Strangar (gerhard brue net)
Re: Buffer overflow prevention Aug 14 2003 08:09PM
Matt D. Harris (vesper depraved org)
Re: Buffer overflow prevention Aug 14 2003 07:17PM
Timo Sirainen (tss iki fi) (1 replies)
Re: Buffer overflow prevention Aug 14 2003 08:15PM
Jedi/Sector One (j pureftpd org) (1 replies)
Re: Buffer overflow prevention Aug 15 2003 09:54AM
Peter Busser (peter trusteddebian org)
Re: Buffer overflow prevention Aug 14 2003 06:47PM
Jedi/Sector One (j pureftpd org) (2 replies)
Re: Buffer overflow prevention Aug 15 2003 09:41AM
Peter Busser (peter trusteddebian org) (2 replies)
Re: Buffer overflow prevention Aug 16 2003 01:36AM
Mark Tinberg (mtinberg securepipe com) (2 replies)
Re: Buffer overflow prevention Aug 18 2003 08:43PM
Crispin Cowan (crispin immunix com)
Re: Buffer overflow prevention Aug 18 2003 08:41PM
Peter Busser (peter trusteddebian org)
Re: Buffer overflow prevention Aug 15 2003 05:55PM
stealth (stealth segfault net)
Re: Buffer overflow prevention Aug 14 2003 08:24PM
Miod Vallat (miod online fr)
Re: Buffer overflow prevention Aug 14 2003 06:27PM
Thomas Sjögren (thomas northernsecurity net)
Re: [Full-Disclosure] Re: Buffer overflow prevention Aug 14 2003 04:51PM
KF (dotslash snosoft com)


 

Privacy Statement
Copyright 2010, SecurityFocus