BugTraq
http://www.smashguard.org Jan 30 2004 11:34PM
Hilmi Ozdoganoglu (cyprian purdue edu) (2 replies)
Re: http://www.smashguard.org Feb 04 2004 05:26AM
Leon Harris (leon quoll com) (1 replies)
Re: http://www.smashguard.org Feb 05 2004 06:06PM
Seth Arnold (sarnold wirex com)
On Wed, Feb 04, 2004 at 01:26:29PM +0800, Leon Harris wrote:
> Certain apps (notably java virtual machines) manipulate stack return
> addresses. I understood that one of the advantages of Immunix's product
> StackGuard was that you could still run these types of apps by
> statically linking them against a normal libc (and chrooting them or
> otherwise confining them). If the protection is mandatory, and in
> hardware, then surely these types of app wont work.

Leon, the limitations with StackGuard and Java Just in Time compilers
and virtual machines have been removed with newer versions of
StackGuard. StackGuard 2, based on egcs (gcc 2.91.66), had an unfortunate
location in the stack layout for the canary which caused problems for
applications that 'knew' the stack layout well enough to introspect
the stack.

Newer versions of StackGuard have since remedied the location of the
canary (to be more secure, while we're at it) such that applications that
are stack-introspective no longer need to be patched to know a 'new'
stack layout. StackGuard 3 uses a better location that is transparent
to gdb, mozilla, JITs, etc.

Of course, I don't want to say what forms of applications may or may not
run on a SmashGuard system; however, the JVMs and JITs may or may not
function on SmashGuard on their own merits -- it was a limitation of
earlier StackGuard releases that caused problems for JVMs, JITs, gdb,
mozilla, etc.

Further information on StackGuard 3 may be found at:
http://immunix.org/stackguard.html

More information will be posted to this page as StackGuard continues
development, and we will periodically announce new developments to the
low traffic immunix-announce mail list:
http://mail.immunix.com/mailman/listinfo/immunix-announce

Thanks Leon

--
Immunix Secured Linux Distribution: http://immunix.org/

[ reply ]
RE: http://www.smashguard.org Feb 03 2004 12:36PM
Dave Paris (dparis w3works com) (2 replies)
RE: http://www.smashguard.org Feb 06 2004 08:29PM
Hilmi Ozdoganoglu (cyprian purdue edu) (3 replies)
Re: http://www.smashguard.org Feb 07 2004 11:44PM
Crispin Cowan (crispin immunix com) (2 replies)
Re: http://www.smashguard.org Apr 29 2004 09:55PM
Pavel Machek (pavel ucw cz) (3 replies)
Re: http://www.smashguard.org May 01 2004 01:56AM
Coleman Kane (cokane cokane org)
Re: http://www.smashguard.org May 01 2004 12:45AM
Theo de Raadt (deraadt cvs openbsd org)
Re: http://www.smashguard.org Apr 29 2004 11:24PM
Crispin Cowan (crispin immunix com) (2 replies)
Re: http://www.smashguard.org May 01 2004 12:28AM
Theo de Raadt (deraadt cvs openbsd org)
Re: http://www.smashguard.org Apr 29 2004 11:29PM
Pavel Machek (pavel ucw cz) (1 replies)
Re: http://www.smashguard.org May 01 2004 02:12AM
Nicholas Weaver (nweaver CS berkeley edu)
Re: http://www.smashguard.org Feb 10 2004 12:04AM
Theo de Raadt (deraadt cvs openbsd org)
Re: http://www.smashguard.org Feb 07 2004 06:11PM
Nicholas Weaver (nweaver CS berkeley edu)
Re: http://www.smashguard.org Feb 07 2004 03:27PM
Theo de Raadt (deraadt cvs openbsd org) (1 replies)
Re[2]: http://www.smashguard.org Feb 07 2004 08:58PM
Andrey Kolishak (andr sandy ru)
Re: http://www.smashguard.org Feb 03 2004 07:01PM
Nicholas Weaver (nweaver CS berkeley edu)


 

Privacy Statement
Copyright 2010, SecurityFocus