Joined February 2010
haha, protip from an unprofessional liar? that's rich ;)
if you're unsure if a given exploit technique is in scope just ask me.
2
Replying to @comex @bsdaemon
hey, why don't you go for it tiger, show us you're competent in more than doling out 'expert' opinion on things you don't understand ;).
1
you sound like the peanut gallery instead. you've been 'interested' in so many things so far with zero accomplishments ;).
you're wrong, nothing changed there. perhaps you too are confused between deterministic vs. probabilistic? read my H2HC15 slides then.
2
2
you can compile a kernel so cut your teeth on the public version first and see how you fare then we'll talk about the next step.
2
2
more lies ;). do you understand the difference between 'probabilistic' and 'deterministic'?
the deterministic return protection was always going to be part of the public release. any more lies up your sleeve? ;)
more lies? i thought you were caught enough times already to know better than that :).
not much based on your experience which isn't much either? :) hint: it took me 2 months to clean up the bad use of fptrs in a 1MB patch.
1
2
in your expert opinion what does scripts/gcc-plugins/rap_plugin/rap_ret_pass.c do? oopsie... you goofed up again ;)
the only people ever complain are those we exposed as liars or incompetent or dishonest. broke a few egos sure, yourself included ;).
you clearly have no idea what it took to protect linux with RAP. it's the *most* complex feature of PaX by far.
1
2
Replying to @kangsterizer
the code has always been and is still GPLv2 but it's no longer distributed to the general public.
1
1
2
Replying to @comex
you mean the gcc codegen 'feature' when frame ptrs are enabled? imagine it's fixed or frame ptrs are off and work from there.
1
1
Replying to @comex
that's kinda the point, these flareups are just that. but hey, do keep trying, i'd actually like to see some real research for a change!
3
1
2
Replying to @comex
uhm, that's about as likely to happen as that exploit you promised a year ago, isn't it? ;)
1
2
We are passing the baton: grsecurity.net/passing_the_b…
10
102
13
61
a new blog from spender about CVE-2017-NOTREALLY grsecurity.net/the_infoleak_…
52
1
59
Replying to @lvwr
i believe you can do (and expect to get) competitive comparisons in any field of research without flames. what were the other reasons?