oh i see grsecurity has /finally/ published their RAP thing, and they still claim it is “ROP-proof”. I guess I should go break it.
4
13
1
45
took a very quick look - am I missing something or is there no protection on memcpy? is that something reserved for the full version? -_-
3
2
10
and on some functions the return address check is just wrong. like this - see the problem? ghostbin.com/paste/kwznb
2
this is why the commercial version is claimed to be ROP-proof. lots of little things under the hood there ;).
1
1
pax_ret is the return addr encryption, right? well, I'd be interested in seeing the implementation… if it ever becomes public
1
1
Replying to @comex
it's a general macro to help instrument assembly code. right now only KERNEXEC makes use of it but i'll add RAP too.

Feb 9, 2017 · 8:38 PM UTC

1
Replying to @paxteam @comex
the asm instrumentation is really no different from what the plugin does though so you can study/work with that.