Firewall Wizards mailing list archives
Re: Here is my plan for firewall implementation
From: Peter Jeremy <peter.jeremy () alcatel com au>
Date: Tue, 23 Sep 1997 06:51:35 +1000 (EST)
On Mon, 22 Sep 1997 12:01:57 -0400 (EDT), "Joseph S. D. Yao" <jsdy () cospo osis gov> wrote: [MJR's suggestion re non-executable stack]
possibly the Sparc do[es] not.
Actually, most SPARCs can. Casper Dik <Casper.Dik () Holland Sun COM> posted some code to BUGTRAQ in November 1996 for Solaris 2.4/2.5/2.5.1 on sun4m and sun4u architectures (although it doesn't work on the sun4c). (It patches 1 word and 1 half-word). Keep in mind that a non-executable stack _will_ break code, although this is probably not a major issue on a firewall. The problems I am aware of are: 1) GCC trampolines (used for nested functions from memory) 2) Interleaf Tool Manager (which you'd better not be running on your firewall in any case).
Software implementations slow the system down, unforgivable to the Marketing departments [;-)].
Given that the slow-down is measured in orders of magnitude, I suspect the engineers wouldn't like it either. :-) Peter -- Peter Jeremy (VK2PJ) peter.jeremy () alcatel com au Alcatel Australia Limited 41 Mandible St Phone: +61 2 9690 5019 ALEXANDRIA NSW 2015 Fax: +61 2 9690 5247
Current thread:
- Re: Here is my plan for firewall implementation, (continued)
- Re: Here is my plan for firewall implementation Bennett Todd (Sep 22)
- Re: Here is my plan for firewall implementation Craig Brozefsky (Sep 21)
- Re: Here is my plan for firewall implementation Marcus J. Ranum (Sep 21)
- Re: Here is my plan for firewall implementation Craig Brozefsky (Sep 22)
- NCSA's RECON Service Adept (Sep 22)
- Re: Here is my plan for firewall implementation Joseph S. D. Yao (Sep 22)
- Re: Here is my plan for firewall implementation Adam Shostack (Sep 22)
- Re: Here is my plan for firewall implementation Paul D. Robertson (Sep 23)
- Re: Here is my plan for firewall implementation Alfred Huger (Sep 24)
- Re: Here is my plan for firewall implementation Marcus J. Ranum (Sep 21)