Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 27 Oct 2005 08:35:31 +0200
From:      jimmy@inet-solutions.be
To:        db <db@traceroute.dk>
Cc:        freebsd-security@freebsd.org
Subject:   Re: Non-executable stack
Message-ID:  <1130394931.43607533be6d7@webmail.boxke.be>
In-Reply-To: <200510270608.51571.db@traceroute.dk>
References:  <200510270608.51571.db@traceroute.dk>

next in thread | previous in thread | raw e-mail | index | archive | help
Quoting db <db@traceroute.dk>:

> Hi all
>
> Does FreeBSD support a non-executable stack on any of the tier 1 and 2
> platforms that has this feature?
> If not, are there any plans of implementing this and is there a patch I can
> use for 6.0 (when it is released)?
>
> Best regards
> db


Hi,

I don't think it will ever be in FreeBSD, but I used ProPolice in the past:

http://www.research.ibm.com/trl/projects/security/ssp/buildfreebsd.html

The patch should be for 5.x in general, I don't use it anymore since some
ports will break, if you play with it you can disable it by default and
enable it explicit when you are willing to compile a binary with it.

Once applied and compiled the whole base with it enabled, you cannot just
turn back!

Kind regards,
Jimmy Scott

----------------------------------------------------------------
This message has been sent through ihosting.be
To report spamming or other unaccepted behavior
by a iHosting customer, please send a message 
to abuse@ihosting.be
----------------------------------------------------------------



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?1130394931.43607533be6d7>