Re: two things

linux kernel account (linker@nightshade.z.ml.org)
Thu, 18 Dec 1997 18:59:22 -0500 (EST)


On Thu, 18 Dec 1997, C. Scott Ananian wrote:

> On Thu, 18 Dec 1997 Jon Lewis <jlewis@inorganic5.fdt.net> wrote:
> My understanding is that the current nonexec-stack patch works so well
> because it cleverly disables itself when it detects code that will break.
> Although this does make it compatible, it doesn't make it secure.
> Solutions to these problems have been rumoured for Linux 2.3.X.

I want to point out that I have offered cash for someone to find an
exploit that still works with no-exec stack... Yes, it's still possible
BUT very difficult. The hack must either look like a trampolene or be in
an app where a tram is occuring..