From owner-freebsd-security Fri Feb 16 13:46:33 2001 Delivered-To: freebsd-security@freebsd.org Received: from point.osg.gov.bc.ca (point.osg.gov.bc.ca [142.32.102.44]) by hub.freebsd.org (Postfix) with ESMTP id 2DF6937B4EC; Fri, 16 Feb 2001 13:46:26 -0800 (PST) Received: (from daemon@localhost) by point.osg.gov.bc.ca (8.8.7/8.8.8) id NAA04042; Fri, 16 Feb 2001 13:45:46 -0800 Received: from passer.osg.gov.bc.ca(142.32.110.29) via SMTP by point.osg.gov.bc.ca, id smtpda04040; Fri Feb 16 13:45:44 2001 Received: (from uucp@localhost) by passer.osg.gov.bc.ca (8.11.2/8.9.1) id f1GLjcd77125; Fri, 16 Feb 2001 13:45:38 -0800 (PST) Received: from cwsys9.cwsent.com(10.2.2.1), claiming to be "cwsys.cwsent.com" via SMTP by passer9.cwsent.com, id smtpdO77120; Fri Feb 16 13:44:48 2001 Received: (from uucp@localhost) by cwsys.cwsent.com (8.11.2/8.9.1) id f1GLikr30835; Fri, 16 Feb 2001 13:44:46 -0800 (PST) Message-Id: <200102162144.f1GLikr30835@cwsys.cwsent.com> Received: from localhost.cwsent.com(127.0.0.1), claiming to be "cwsys" via SMTP by localhost.cwsent.com, id smtpdK30829; Fri Feb 16 13:44:28 2001 X-Mailer: exmh version 2.3.1 01/18/2001 with nmh-1.0.4 Reply-To: Cy Schubert - ITSD Open Systems Group From: Cy Schubert - ITSD Open Systems Group X-Sender: schubert To: Hiroaki Etoh , kris@freebsd.org Cc: security@freebsd.org, ash@lab.poc.net, kjm@rins.ryukoku.ac.jp, iwamura@muraoka.info.waseda.ac.jp Subject: Re: Base system with gcc stack-smashing protector In-reply-to: Your message of "Fri, 16 Feb 2001 18:26:25 +0900." <20010216182625I.etoh@trl.ibm.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Date: Fri, 16 Feb 2001 13:44:28 -0800 Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org Any idea when this might be merged into the base tree? Regards, Phone: (250)387-8437 Cy Schubert Fax: (250)387-5766 Team Leader, Sun/Alpha Team Internet: Cy.Schubert@osg.gov.bc.ca Open Systems Group, ITSD, ISTA Province of BC In message <20010216182625I.etoh@trl.ibm.com>, Hiroaki Etoh writes: > On 17 Nov, Kris Kennaway wrote: > > This was trivial to get working on FreeBSD, but here is a patch > > against the system gcc in 4.x which will compile a ProPolice-enabled > > version, so FreeBSD users can start easily making use of this. The > > patch is the same for 5.x users except you will need to replace > > "contrib/gcc" with "contrib/gcc.295" in the diff. > > > > http://www.freebsd.org/~kris/protector.patch > > Iwamura-san and Etoh have finished to build the stack protected version > of FreeBSD base system! Iwamura-san fixed several linkage errors > generated from the above patch. > > We confirmed the protected system blocked the bind TSIG exploit which is > announced from CERT, 31 Jan, 2001. > > Here is a patch against the system 4.2-RELEASE. > http://www.trl.ibm.co.jp/projects/security/ssp/protector.patch > > See http://www.trl.ibm.co.jp/projects/security/ssp/buildfreebsd.html for > details. > > We are still working on building the protected version of kernel. > > Hiroaki Etoh, > Tokyo Research Laboratory, IBM Japan > > Makoto Iwamura, > Muraoka Lab., Waseda University > > > > > To Unsubscribe: send mail to majordomo@FreeBSD.org > with "unsubscribe freebsd-security" in the body of the message To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message