Un article de Bulba and Kil3r paru dans Phrack n°56 rappelait déjà (2000) que les outils de protection se révélaient 'insuffisants' car pouvant eux même être déjoués (h3h3). Ils concluaient en préconisant leur utilisation en application du principe de précaution et en rappelant que la qualité du code est une Nécessité, tout comme son audit.
----| Conclusion
1) StackGuard/StackShield can save you in case of accidental buffer overflows,
but not against a programmer's stupidity. Erreare humanum est, yeah
right, but security programmers must not only be human, they must be
security-aware-humans.
2) - By auditing your code - you may waste some time but you'll surely
increase the security of the programs you're writing.
- By using StackGuard/StackShield/whatever - you may decrease your system
performance but in turn you gain additional layer of security.
- By doing nothing to protect your program - you risk that someone will
humiliate you by exploiting an overflow in your code, and if it happens,
you deserve it!
So, be perfect, be protected, or let the others laugh at you.
# Re: Exec Shield: protection contre les débordements de tampons
Posté par hideo . En réponse à la dépêche Exec Shield: protection contre les débordements de tampons. Évalué à 4.
----| Conclusion
1) StackGuard/StackShield can save you in case of accidental buffer overflows,
but not against a programmer's stupidity. Erreare humanum est, yeah
right, but security programmers must not only be human, they must be
security-aware-humans.
2) - By auditing your code - you may waste some time but you'll surely
increase the security of the programs you're writing.
- By using StackGuard/StackShield/whatever - you may decrease your system
performance but in turn you gain additional layer of security.
- By doing nothing to protect your program - you risk that someone will
humiliate you by exploiting an overflow in your code, and if it happens,
you deserve it!
So, be perfect, be protected, or let the others laugh at you.
---[ BYPASSING STACKGUARD AND STACKSHIELD ]
Bulba and Kil3r, < http://www.phrack.org/phrack/56/p56-0x05(...)>
non mais 8).
A lire pour atteindre l'éveil 0:)
---[ A Brief History of Hackerdom ]
http://www.l0t3k.org/biblio/hacking/english/hacker-history/(...)
ou cette approche du développement "sécurisé"
---[ Best Practices for Secure Development ]
Razvan Peteanu < http://members.rogers.com/razvan.peteanu/best_prac_for_sec_dev4.pdf(...)>
---[ How to find security holes ]
paulv < http://www.l0t3k.org/biblio/programming/english/security-holes.html(...)>
< http://www.canonical.org/(...)>
---[ Secure Programming for Linux and Unix HOWTO ]
David A. Wheeler < http://www.dwheeler.com/secure-programs/(...)>
---[ Secure UNIX Programming FAQ ]
< http://www.whitefang.com/sup/(...)>
Le vent nous portera...
hideo_nomura