3 ms·
Yup, defense-in-depth requires broad(coverage) and deep(overlapping) holistic solutions. There’s too many defenses on too many platforms to enumerate comprehens
by king_nothing 8y ago
Yup, defense-in-depth requires broad(coverage) and deep(overlapping) holistic solutions. There’s too many defenses on too many platforms to enumerate comprehensively, but they’re discoverable.
Afl for overall fuzzing:
http://lcamtuf.coredump.cx/afl http://lcamtuf.coredump.cx/afl
Klee for generating minimal test-cases automatically:
http://klee.github.io http://klee.github.io (by LLVM)
Property-based testing to specify test-cases manually:
https://github.com/silentbicycle/theft https://github.com/silentbicycle/theft
http://www.quviq.com/products http://www.quviq.com/products
Toolchain docs:
https://clang.llvm.org/docs https://clang.llvm.org/docs
https://gcc.gnu.org/onlinedocs https://gcc.gnu.org/onlinedocs
Binutils gold (new ld) linker https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=tree;f=gold https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=t...
Compiler defensive best-practices source docs:
https://blog.quarkslab.com/clang-hardening-cheat-sheet.html https://blog.quarkslab.com/clang-hardening-cheat-sheet.html
https://security.stackexchange.com/questions/24444/what-is-the-most-hardened-set-of-options-for-gcc-compiling-c-c#24840 https://security.stackexchange.com/questions/24444/what-is-t...
https://www.phoronix.com/scan.php?page=news_item&px=GNU-Glibc-2.27-Released https://www.phoronix.com/scan.php?page=news_item&px=GNU-Glib...
PIE and PIC
https://stackoverflow.com/q/2463150/246672 https://stackoverflow.com/q/2463150/246672
https://www.netbsd.org/gallery/presentations/khorben/asiabsdcon2017/Hardening%20pkgsrc.pdf https://www.netbsd.org/gallery/presentations/khorben/asiabsd...
https://edgeofus.com/information-security-2/how-to-harden-cc-programs-through-defensive-compilation/ https://edgeofus.com/information-security-2/how-to-harden-cc...
https://developers.redhat.com/blog/2018/03/21/compiler-and-linker-flags-gcc/ https://developers.redhat.com/blog/2018/03/21/compiler-and-l...
https://fedoraproject.org/wiki/Changes/Harden_All_Packages https://fedoraproject.org/wiki/Changes/Harden_All_Packages
https://www.owasp.org/index.php/C-Based_Toolchain_Hardening https://www.owasp.org/index.php/C-Based_Toolchain_Hardening
and lots of reading man pages for latest code and DuckDuckGoing