Re: Exploit mitigation techniques and kernel code

2007-03-17 Thread Jeroen Massar
Theo de Raadt wrote: [..] >> privilege revocation/separation, > > split the kernel? huh? Well, one could do it, but then you end up with a micro-kernel or at least something that passes, and verifies, messages between the components which run in separate subsystems. Having it compartmentali

Re: Exploit mitigation techniques and kernel code

2007-03-17 Thread Theo de Raadt
> after reading the recent CORE advisory about the mbuf handling bug, I > was wondering if some of OpenBSD's exploit mitigation strategies could > also be applied to the kernel in order to prevent exploitation of kernel > bugs. Theo's presentation about exploit mitigation ( > http://openbsd.org

Exploit mitigation techniques and kernel code

2007-03-17 Thread Andreas Bartelt
Hi all, after reading the recent CORE advisory about the mbuf handling bug, I was wondering if some of OpenBSD's exploit mitigation strategies could also be applied to the kernel in order to prevent exploitation of kernel bugs. Theo's presentation about exploit mitigation ( http://openbsd.org