4 ms·
Alternate title: "It's Probably Fine: Continuing to Ship Unsafe Programs by Pretending ROP Doesn't Exist".
by ctz 9y ago
Alternate title: "It's Probably Fine: Continuing to Ship Unsafe Programs by Pretending ROP Doesn't Exist".
- mrich 9y agoCould you be a bit more specific? As can be seen from the article, this is one part of a series describing several best practices you should follow when shipping binaries. This one article does not claim to cover everything. Also check part 1 and the upcoming ones. Also, if there is a defense against ROP and other exploits that makes it possible to do away with ASLR and ESP please let me know.
- ctz 9y ago> Also, if there is a defense against ROP and other exploits that makes it possible to do away with ASLR and ESP please let me know. Memory safety. Everything else (ASLR, DEP, CFI, heap hardening, etc.) is just fiddling around the edges -- it's not an engineering approach that produces reliable or safe software.
- mrich 9y agoAgreed; but until we get there, we must make sure the software we ship from existing codebases is as safe/unexploitable as possible.
- MichaelMoser123 9y agoROP has problems with ALSR on 64 bit machine. Security is not a binary on off thing. The harder you make it for the attacker, the better. (however ALSR makes it difficult to deal with core dumps, ouch)
- AstralStorm 9y agoASLR often makes it a requirement to get data disclosure (heap layout or at least GOP) before a full break. A funny thing is that a fully static LTO processed and inlined app is extremely hard to crack once ASLR is in play since you get no returns and get to mess only with what is inside. (Unless you find some dlopen, exec or system, perhaps mmap with unsafely handled flags.) Add good NX and read only pages and it becomes a real puzzle. And no, it does not make dealing with debugging info equipped dumps any harder, as long as walking the stack is all you need.
- pcwalton 9y ago> A funny thing is that a fully static LTO processed and inlined app is extremely hard to crack once ASLR is in play since you get no returns and get to mess only with what is inside. How often does that actually happen? On macOS and Windows the answer should be "never" since the syscall ABI is not stable...
- gok 9y ago> On macOS and Windows the answer should be "never" since the syscall ABI is not stable... Dear Golang...
- user5994461 9y ago#define WINAPI __stdcall The windows API ABI is stable and unchanged for decades.
- AstralStorm 9y agoOn both of these platforms, ABIs and APIs are stable until you get to drawing. Which means you should probably use real process separation for the GUI - it has to be linked dynamically.
- pcwalton 9y agoNo part of the Windows syscall ABI is stable on Windows. Not win32k, not core NTAPI. You need core NTAPI to send IPC messages.
- MikeHolman 9y agoCET is coming out soon, and I'm hopeful that this will make ROP much harder.
- mrich 9y agoHadn't heard about that one before, here are more details: https://software.intel.com/en-us/blogs/2016/06/09/intel-release-new-technology-specifications-protect-rop-attacks https://software.intel.com/en-us/blogs/2016/06/09/intel-rele...
- stcredzero 9y agoNeeds much better editing!