3 ms·
W^X stands for "writable xor executable": > What this means is that each page holding JIT code is either executable or writable, never both at the same time.
by maggit 10y ago
W^X stands for "writable xor executable":
> What this means is that each page holding JIT code is either executable or writable, never both at the same time.
For anybody, like me, who didn't already know :)
- omginternets 10y agoForgive my ignorance -- what does this achieve?
- Diederich 10y agoIf an attacker is able to write arbitrary code through to memory, they won't then be able to actually execute that code. It's a solid security enhancement.
- DarkLinkXXXX 10y agoForgive my naivete, isn't that feature provided by the operating system?
- JonathonW 10y agoIt is provided by the operating system, but you can't just naively enable it by default, especially in an application like Firefox (which has a JIT compiler for Javascript, and therefore needs to be aware of and able to manage which pages are writable and which pages are executable).
- neerdowell 10y agoSoftware has to play nice and not request WX pages. If they do, the OS does as its asked. See also, Theo de Raadt's recent comment on why OSes can't enforce W^X on userland (yet): https://marc.info/?l=openbsd-misc&m=145943630726937&w=2 https://marc.info/?l=openbsd-misc&m=145943630726937&w=2
- buster 10y agoThat you can't have a bug in your code that lets an attacker overwrite data (aka a buffer overflow writes into memory) AND have that part of memory executed. It's either data (which can be overwritten) or code (which can't be overwritten).
- exDM69 10y agoIt's not a fool proof mitigation for buffer overflow attacks, though. You can still write a bogus return address in a stack overflow and use return oriented programming (ROP) to do exploits with W^X. There are ways to work around address space layout randomization (ASLR) too.
- valarauca1 10y agoNo methodology in Infosec is every 100% prefect. You nest your defenses like Russian Dolls. Each layer of protection fends off another class of attackers. An attacker with infinite determination, money, or time will always push past your defenses.
- stefs 10y agoin reality, at some point it's just not cost effective anymore (for the attacker) and other targets become more promising.
- ben_bai 10y agoNone of these mitigations is perfect. But how do you combine a exploit that has to deal with W^X, ASLR, randomized stack gap, stack cookie, randomized location of shared libraries and static programs. Seems pretty hard to me.
- deleted 10y ago[deleted]
- deleted 10y ago[deleted]