( LiRul | 2003. 12. 02., k – 17:06 )

In My Humble Opinion az, hogy a grsec-es kernel megfogja-e az exploitot erosen fugg a kernelforgataskor beallitott grsec opcioktol. Nalam a (szerintem) idevonatkozo resz igy nez ki:

#

# Address Space Protection

#

CONFIG_GRKERNSEC_PAX_NOEXEC=y

# CONFIG_GRKERNSEC_PAX_PAGEEXEC is not set

CONFIG_GRKERNSEC_PAX_SEGMEXEC=y

# CONFIG_GRKERNSEC_PAX_EMUTRAMP is not set

CONFIG_GRKERNSEC_PAX_MPROTECT=y

# CONFIG_GRKERNSEC_PAX_NOELFRELOCS is not set

CONFIG_GRKERNSEC_PAX_ASLR=y

CONFIG_GRKERNSEC_PAX_RANDKSTACK=y

CONFIG_GRKERNSEC_PAX_RANDUSTACK=y

CONFIG_GRKERNSEC_PAX_RANDMMAP=y

CONFIG_GRKERNSEC_PAX_RANDEXEC=y

CONFIG_GRKERNSEC_KMEM=y

CONFIG_GRKERNSEC_IO=y

CONFIG_RTC=y

CONFIG_GRKERNSEC_PROC_MEMMAP=y

CONFIG_GRKERNSEC_HIDESYM=y