Debian Developers - Re: Steve Kemp <skx@debian.org> Please check your Debian E-Mail.

This is Interesting: Free IT Magazines  
Home > Archive > Debian Developers > August 2005 > Re: Steve Kemp <skx@debian.org> Please check your Debian E-Mail.





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author Re: Steve Kemp <skx@debian.org> Please check your Debian E-Mail.
Steve Kemp

2005-08-03, 7:51 am

On Tue, Aug 02, 2005 at 03:58:33PM -0400, Greg Folkert wrote:

> I was finally able to acquire an SSP Build Host for you.
> If you are still interest. Please contact me.


A bit quick off the mark there, Greg! I think I've replied to all
your previous mails within a day or two...?

Anyway for anybody else watching. This host is going to be used
for rebuilding Debian's Stable release, Sarge, with the SSP
compiler.

The SSP compiler is a patch against GCC and offers "Stack Smashing
Protection". In short it gives protection against buffer overflow
bugs, and attacks.

Whilst it doesn't protect a system in all cases, and other
avenues of exploitation are still available (eg, format string
attacks) it's a good means of hardening the system.

The big drawback with using SSP is that it is a compiler based
security system, so to use it all system binaries must be rebuilt.

The intention is *not* to create a new distribution, like
Adamantix[1]. I've neither the skill, intention, or the patience
to support a full distribution. Instead the goal is twofold:

1. See if there is any interest in supporting this in Debian.

2. See if it all actually works. (eg. #213994, #233208).

Steve
--
[1] http://www.adamantix.org/
- Last updated news page 2004-08-17


--
To UNSUBSCRIBE, email to debian-devel-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Sponsored Links






Free braindumps | Software forum | Database administration forum

Copyright 2003 - 2008 webservertalk.com