On 10/20/16 11:46, Lampshade wrote: >> if you read the paper, you will notice that they only tested on Ubuntu and >> OSX, >> neither of which actually ship with ASLR enabled by default if I remember >> correctly. > > https://wiki.ubuntu.com/Security/Features
which claims that ASLR is indeed enabled by default in all recent Ubuntu releases. Well, something in this story doesn't quite fit. Until we see the actual code, and a credible demonstration, I remain unconvinced that the paper tells the whole truth. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.