Dailydave mailing list archives

Re: Default Deny on Executables


From: Eduardo Tongson <propolice () gmail com>
Date: Thu, 15 Sep 2005 01:03:22 +0000

The OpenBSD stephanie project too, TPE & Verified Exec.

http://www.innu.org/~brian/Stephanie/

<plea>Abandoned project now, maybe someone here thinks it's cool
enough to pick up </plea>


NetBSD has Verified Exec 
<http://www.netbsd.org/guide/en/chap-whatsnew.html#chap-whatsnew-2-0-veriexec>

Linux can have TPE via grsecurity patches which is quite effective in
dealing with
untrusted user's `machine` code, but certainly the problem with
interpreters still
looms. With the fact that you can write exploits in ruby, perl or
python with the
same effectiveness as one written in C further complicates the blur between
`machine` code and an interpreted script.

--ed

Current thread: