The details on loading rootkits via /dev/mem
The details on loading rootkits via /dev/mem
Posted Apr 29, 2009 9:17 UTC (Wed) by nix (subscriber, #2304)In reply to: The details on loading rootkits via /dev/mem by dersteppenwolf
Parent article: The details on loading rootkits via /dev/mem
that either PaX nor grsecurity were bad. I've used both and think they're
excellent pieces of work and that both the anonymous PaXteam and spender
are superb at spotting holes. They're just hopeless at the social-oil part
which makes it even slightly plausible that anyone else will pick up what
they do in any larger project.
(And, well, I had a dig. One comment during the 2.6 freeze, obviously
hopeless. An attempt by Valdis to split up the non-duplicative-of-LSM,
non-ASLR stuff in 2004: James Morris thought most the remaining bits were
of minimal security benefit (I agree with Valdis here: it's an extra bar,
so what if it's low, the cost is low too), but the thing had a BSD
advertising clause at the time so couldn't possibly go in. A thread in
2005 which foundered in flames, disagreements over worthwhile tradeoffs,
and claims (from a third party) that grsecurity was intrinsically
impossible to split up, which at a then size of 700K would make it
intrinsically impossible to ever merge. I've looked at every archived l-k
message ever to mention grsecurity, and there's no sign that anyone other
than Valdis ever tried to split it up at all.)
... sheesh, why am I even responding to someone whose idea of cogent
argument is poo jokes and threats of identity disclosure? I must be bored.