This is the mail archive of the
gcc@gcc.gnu.org
mailing list for the GCC project.
Re: machine independent protection from stack-smashing attack
- To: "Hiroaki Etoh" <ETOH at jp dot ibm dot com>, gcc at gcc dot gnu dot org
- Subject: Re: machine independent protection from stack-smashing attack
- From: "Matt Minnis" <mminnis at prefres dot com>
- Date: Tue, 08 Aug 2000 11:32:06 -0500
Would this be as an option or for all compiled code?
I would greatly prefer it to be --use_stack_smash (or whatever)
This way for people who do not need it for their application, it can be
left out.
Thanks,
Matt Minnis
At 12:01 AM 8/9/2000 +0900, Hiroaki Etoh wrote:
>I have been investigating a machine-independent change to GCC that
>would generate code to protect applications from stack-smashing attacks.
>The main characteristics are low performance overhead of the protection
>code, protecting against different varieties of stack-smashing attacks,
>and supporting various processors. A research report is ready on
>the web (http://www.trl.ibm.co.jp/projects/security/propolice).
>
>I would like some feedback whether it is worth pursuing getting it
>assigned to the FSF for inclusion in GCC.
>
>---
>Hiroaki Etoh, Tokyo Research Laboratory, IBM Japan
Cthulhu for President. Why settle for a lesser evil?
=========================================================
Preferred Resources (314) 567-7600 phone
701 Emerson rd. (314) 993-6699 fax
Suite 475 mminnis@prefres.com
St. Louis, MO
63141
=========================================================