3 ms·
Since PTRACE (which is one easy way to do this) is part of POSIX, does this mean Windows no longer has a POSIX subsystem? Edit: I guess only Server and Enterpr
by voidlogic 11y ago
Since PTRACE (which is one easy way to do this) is part of POSIX, does this mean Windows no longer has a POSIX subsystem?
Edit: I guess only Server and Enterprise have POSIX: http://brianreiter.org/2010/08/24/the-sad-history-of-the-microsoft-posix-subsystem/ http://brianreiter.org/2010/08/24/the-sad-history-of-the-mic...
- munin 11y agoptrace is not an easy way to do this... if you try and make an anti-virus or HIPS system based around ptrace you're going to have a very bad day (it's slow, attackers can detect it) the "normal" way this was done was to have your kernel driver replace system call implementations with wrappers that check an alternate security policy. this was done so often that linux implemented loadable security modules (LSM) and then SELinux on top of that, while other systems (grsec, rbac) exist as patches. it was also one of the main causes of system instability on windows because the people that wrote the wrapper functions did not understand nearly as much about the operating system as they thought, and introduced at best crashes and at worst outright vulnerabilities. so microsoft created a technology that stopped people from patching their kernel in that way. okay, in the game of cat-and-also-cat that is systems security in the same kernel-level privilege domain it doesn't "stop" them technically it "deters" them but the protection system is semi-random and silently updates, so if you figure out a way to break it and then later your clever hack is silently broken your customers computer will crash in a way that says "hey this one particular product just broke the rules and you should uninstall it" and why run that risk. they replaced it with a bunch of mature callback APIs that let you do kinda the same thing but with less chance of fucking everything up.