oh i see grsecurity has /finally/ published their RAP thing, and they still claim it is “ROP-proof”. I guess I should go break it.
4
13
1
45
took a very quick look - am I missing something or is there no protection on memcpy? is that something reserved for the full version? -_-
3
2
10
and on some functions the return address check is just wrong. like this - see the problem? ghostbin.com/paste/kwznb
2
this is why the commercial version is claimed to be ROP-proof. lots of little things under the hood there ;).
1
1
it's a general macro to help instrument assembly code. right now only KERNEXEC makes use of it but i'll add RAP too.
Feb 9, 2017 · 8:38 PM UTC
1

