4 ms·
NX does not need to be disabled[1] for the binary thanks to W^X[0]. As long as pages are never mapped as writeable and executable at the same time, you don't lo
by exrook 8y ago
NX does not need to be disabled[1] for the binary thanks to W^X[0]. As long as pages are never mapped as writeable and executable at the same time, you don't lose any protection.
[0] https://en.wikipedia.org/wiki/W%5EX https://en.wikipedia.org/wiki/W%5EX
[1] AFAIK, on Linux NX isn't something that is enabled or disabled for individual programs anyways, it's up to the userland whether or not it takes advantage of the mmap(2) mapping flags
- bdonlan 8y agoIn general, you lose some protection, as a two-stage exploit might write some data in W state then flip to (or wait for) X state for execution. That being said, a self-decompressing binary would only do this at startup, before it consumes untrusted input, so given a way to drop map-executable permissions that wouldn't be a problem.