6 ms·
Folks from OPN and HBSD appear to have rudimentary grasp of C while making grandiose security claims. This is probably my favorite feature comparison of all tim
by nAwYz 8y ago
Folks from OPN and HBSD appear to have rudimentary grasp of C while making grandiose security claims. This is probably my favorite feature comparison of all time https://hardenedbsd.org/content/easy-feature-comparison https://hardenedbsd.org/content/easy-feature-comparison. It appears to be largely cult of personality ensnaring users that don't really know any better
Could you explain whats bad about that comparison? Or point to an example of their "rudimentary grasp of C" ?
- kev009 8y agoThe comparison is cherry picked cargo cult. ASLR and a lot of these mitigations were obsolete when HBSD implemented them https://www.endgame.com/blog/technical-blog/rop-dying-and-your-exploit-mitigations-are-life-support https://www.endgame.com/blog/technical-blog/rop-dying-and-yo.... Their ASLR try was rejected by FreeBSD.org. Some of the bullets are completely asinine like xxx hardening, what does that even mean? The lead developer recently gave a conference talk where as far as I can tell he showed that you can root a box as.. root https://www.youtube.com/watch?v=bT_k06Xg-BE https://www.youtube.com/watch?v=bT_k06Xg-BE. Can anyone point to a paper showing where HBSD successfully prevented an attack over FreeBSD? So they generate a lot of noise. Instead of learning from the larger communities that are filled with extremely talented security people like Colin "cperciva" Percival, Robert Watson, Theo de Raadt, Maxime Villard, etc Shawn seems hellbent on being an exemplar of Dunning-Kruger effect. Unfortunately he is towing others along for the ride.
- auslander 8y agoASLR is obsolete? Why?
- kev009 8y agoSorry, you didn't bother reading the link so you may consult Google if you are interested.
- auslander 8y agoThe link is not about ASLR, but ROP. ROP != ASLR :) Anyway, even there, we can read : "ASLR aims to prevent an attacker from using previous knowledge of the address space to gain an advantage and execute malicious code. This has proven extremely effective in “raising the bar” of exploitation and is one of the most significant research challenges" So, back to square one, why ASLR is obsolete? Its one of the main security features. Recap: OPNsense uses HardenedBSD as base OS, which have ASLR, along with other BSDs. pfSense uses FreeBSD, which don't have ASLR/ASR.
- kev009 8y agoThe first sentence in the article should be a bell-ringer "Too often the defense community makes the mistake of focusing on the what, without truly understanding the why." These are context sensitive things that aren't learned by reading a comment thread, if you can't read that article and understand that it shows a multitude of exploits that bypass ASLR and that almost every exploit and contest includes or relies on existing ASLR bypass I don't really know what to tell you other than to keep reading and researching. The answers you seek are linked from TFA.
- auslander 8y ago>The answers you seek I expect you backing up your statement that ASLR is obsolete. So far all we have is a URL and advice to research ourselves. What stops you from giving a direct answer? Hint: "ASLR is useless, because I can, for example, do this: ..."
- kev009 8y agoMy dude, if you can't read and comprehend how am I supposed to do that for you? The article includes extensive linked references with code examples that are far more credible than me on the subject. What don't you understand here: "As ASLR has improved through 'full' ASLR, attackers have needed to read memory in their exploit code to adequately determine what data to target for a successful exploit. This step in exploit development is one of the most time consuming, but also the most powerful, because in many cases not only can you craft an exploit to read the target address space and bypass ASLR, you can also write into the target address space." If language is a barrier or something, that means, in simple words, ASLR is so minor a speedbump as to be a safety blanket.