On Mon, 2003-02-24 at 04:37, Giuseppe Ghib� wrote: Liam Quin wrote:
Anyone here familiar enough with gcc to comment on StackGuard [1], and whether it'd be a good thing to use for system services/daemons in Mandrake Linux? It looks like it's not been kept up to date.
[1] http://www.immunix.org/stackguard.html
The main problem is that they use obsolete compilers, such as egcs 1.1.2.
Yes, agreed. That's why I sait it looks is if it's not been kept up to date :-)
Maybe this one? http://www.trl.ibm.com/projects/security/ssp/
OK... so, has anyone tried this? :-)
Stack protection might be a big plus for Mandrake Linux in a server environment, although you'd have to measure the performance hit to see if it was worth while on a workstation.
What about libsafe? I haven't looked into it recently, but at one point above a certain security level we enabled it.
