if I read between the lines of this @grsecurity post… PaX doesn’t have userland stack proving and thus isn’t immune, despite claim @ start?
3
(btw, I haven’t forgotten about what I said I’d do, and I will, but it’s demotivating to have to go look for leaks just to prove a point)
1
what leaks do you need? for spraying or content? if the latter, assume you know static addresses/content (vmlinux/modules).
1
by leaks I mean the commercial version of grsecurity
1
Replying to @comex @grsecurity
i believe babies need to take baby steps first, so cut your teeth on the public version that you promised a year ago already ;).

Jun 21, 2017 · 8:48 PM UTC