Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #184937 > unrolled thread
| Started by | "Thomas Schmitt" <scdbackup@gmx.net> |
|---|---|
| First post | 2017-08-09 16:40 +0200 |
| Last post | 2017-08-10 10:00 +0200 |
| Articles | 10 — 6 participants |
Back to article view | Back to linux.debian.user
This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by
below is the oldest one visible, not the original post.
Re: When did Debian decide to enable PIE by default? "Thomas Schmitt" <scdbackup@gmx.net> - 2017-08-09 16:40 +0200
Re: When did Debian decide to enable PIE by default? Gene Heskett <gheskett@shentel.net> - 2017-08-09 16:50 +0200
Re: When did Debian decide to enable PIE by default? Dan Ritter <dsr@randomstring.org> - 2017-08-09 17:10 +0200
Re: When did Debian decide to enable PIE by default? Pascal Hambourg <pascal@plouf.fr.eu.org> - 2017-08-09 20:00 +0200
Re: When did Debian decide to enable PIE by default? Tony van der Hoff <lists@vanderhoff.org> - 2017-08-09 17:30 +0200
Re: When did Debian decide to enable PIE by default? Gene Heskett <gheskett@shentel.net> - 2017-08-10 02:30 +0200
Re: When did Debian decide to enable PIE by default? <tomas@tuxteam.de> - 2017-08-10 10:10 +0200
Re: When did Debian decide to enable PIE by default? Pascal Hambourg <pascal@plouf.fr.eu.org> - 2017-08-12 13:20 +0200
Re: When did Debian decide to enable PIE by default? <tomas@tuxteam.de> - 2017-08-12 16:10 +0200
Re: When did Debian decide to enable PIE by default? <tomas@tuxteam.de> - 2017-08-10 10:00 +0200
| From | "Thomas Schmitt" <scdbackup@gmx.net> |
|---|---|
| Date | 2017-08-09 16:40 +0200 |
| Subject | Re: When did Debian decide to enable PIE by default? |
| Message-ID | <ucAjo-bt-9@gated-at.bofh.it> |
Hi, 慕 冬亮 <mudongliangabcd@hotmail.com> wrote: > When does Debian Team, or Security Team decide to enable PIE by default? I guess it was one year ago. At least that's the dates one can see on https://wiki.debian.org/Hardening/PIEByDefaultTransition Have a nice day :) Thomas
[toc] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2017-08-09 16:50 +0200 |
| Message-ID | <ucAt5-fu-37@gated-at.bofh.it> |
| In reply to | #184937 |
On Wednesday 09 August 2017 10:31:48 Thomas Schmitt wrote: > Hi, > > 慕 冬亮 <mudongliangabcd@hotmail.com> wrote: > > When does Debian Team, or Security Team decide to enable PIE by > > default? > > I guess it was one year ago. At least that's the dates one can see on > https://wiki.debian.org/Hardening/PIEByDefaultTransition > Interesting Thomas, but what the heck is PIE? I know about PAE, but PIE? Whats it do? Searching the above wiki returned only this thread. Thanks, you too. > > Have a nice day :) > > Thomas Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | Dan Ritter <dsr@randomstring.org> |
|---|---|
| Date | 2017-08-09 17:10 +0200 |
| Message-ID | <ucAMr-D4-43@gated-at.bofh.it> |
| In reply to | #184938 |
On Wed, Aug 09, 2017 at 10:48:24AM -0400, Gene Heskett wrote: > On Wednesday 09 August 2017 10:31:48 Thomas Schmitt wrote: > > > Hi, > > > > 慕 冬亮 <mudongliangabcd@hotmail.com> wrote: > > > When does Debian Team, or Security Team decide to enable PIE by > > > default? > > > > I guess it was one year ago. At least that's the dates one can see on > > https://wiki.debian.org/Hardening/PIEByDefaultTransition > > > Interesting Thomas, but what the heck is PIE? I know about PAE, but PIE? > Whats it do? Searching the above wiki returned only this thread. > https://en.wikipedia.org/wiki/Position-independent_code It's a security measure. -dsr-
[toc] | [prev] | [next] | [standalone]
| From | Pascal Hambourg <pascal@plouf.fr.eu.org> |
|---|---|
| Date | 2017-08-09 20:00 +0200 |
| Message-ID | <ucDqW-243-23@gated-at.bofh.it> |
| In reply to | #184939 |
Le 09/08/2017 à 17:05, Dan Ritter a écrit : > On Wed, Aug 09, 2017 at 10:48:24AM -0400, Gene Heskett wrote: >> >> Interesting Thomas, but what the heck is PIE? It is explained in the link posted by Thomas. > It's a security measure. No, PIE is not a security measure per se. It just allows to map an run the executable code anywhere in the address space instead of at a fixed location, which is useful for shared libraries for example. This feature is also used by Address Space Layout Randomization, which is a security measure.
[toc] | [prev] | [next] | [standalone]
| From | Tony van der Hoff <lists@vanderhoff.org> |
|---|---|
| Date | 2017-08-09 17:30 +0200 |
| Message-ID | <ucB5L-Jz-1@gated-at.bofh.it> |
| In reply to | #184938 |
On 09/08/17 15:48, Gene Heskett wrote: > Interesting Thomas, but what the heck is PIE? I know about PAE, but PIE? > Whats it do? Searching the above wiki returned only this thread. > > Thanks, you too. >> Have a nice day :) >> >> Thomas > > Cheers, Gene Heskett Position-independent executable: https://en.wikipedia.org/wiki/Position-independent_code
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2017-08-10 02:30 +0200 |
| Message-ID | <ucJwl-6s8-3@gated-at.bofh.it> |
| In reply to | #184938 |
On Wednesday 09 August 2017 10:52:26 慕 冬亮 wrote: > On 08/09/2017 10:48 AM, Gene Heskett wrote: > > On Wednesday 09 August 2017 10:31:48 Thomas Schmitt wrote: > >> Hi, > >> > >> 慕 冬亮 <mudongliangabcd@hotmail.com> wrote: > >>> When does Debian Team, or Security Team decide to enable PIE by > >>> default? > >> > >> I guess it was one year ago. At least that's the dates one can see > >> on https://wiki.debian.org/Hardening/PIEByDefaultTransition > > > > Interesting Thomas, but what the heck is PIE? I know about PAE, but > > PIE? Whats it do? Searching the above wiki returned only this > > thread. > > Please take a look at the following URL: > > https://wiki.debian.org/Hardening#DEB_BUILD_HARDENING_PIE_.28gcc.2Fg.2 >B-.2B-_-fPIE_-pie.29 > Aha, another name for PIC, which I've only been writing code that uses it for 32 years. Also known as PCR, for Program Counter Relative. Such code can be loaded into memory and executed without any patching. > It is a security feature which combines with ASLR to do full address > space randomization. > > > Thanks, you too. > > > >> Have a nice day :) > >> > >> Thomas > > > > Cheers, Gene Heskett Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2017-08-10 10:10 +0200 |
| Message-ID | <ucQHv-2LF-11@gated-at.bofh.it> |
| In reply to | #184961 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Wed, Aug 09, 2017 at 08:22:58PM -0400, Gene Heskett wrote: > On Wednesday 09 August 2017 10:52:26 慕 冬亮 wrote: > > > On 08/09/2017 10:48 AM, Gene Heskett wrote: > > > On Wednesday 09 August 2017 10:31:48 Thomas Schmitt wrote: > > >> Hi, > > >> > > >> 慕 冬亮 <mudongliangabcd@hotmail.com> wrote: > > >>> When does Debian Team, or Security Team decide to enable PIE by > > >>> default? > > >> > > >> I guess it was one year ago. At least that's the dates one can see > > >> on https://wiki.debian.org/Hardening/PIEByDefaultTransition > > > > > > Interesting Thomas, but what the heck is PIE? I know about PAE, but > > > PIE? Whats it do? Searching the above wiki returned only this > > > thread. > > > > Please take a look at the following URL: > > > > https://wiki.debian.org/Hardening#DEB_BUILD_HARDENING_PIE_.28gcc.2Fg.2 > >B-.2B-_-fPIE_-pie.29 > > > Aha, another name for PIC, which I've only been writing code that uses it > for 32 years. Also known as PCR, for Program Counter Relative. Such > code can be loaded into memory and executed without any patching. Not exactly. PIC is "position independent code". Shared libraries have been compiled like that for a long time since (especially under 32 bits) you never knew where was a hole in memory to mmap the library in. PIE is "position independent executable": it's about using PIC in the Executable -- since that's the first to map in, the whole (well, nearly) address space is available, and there's no need to generate PIC. Since (under Intel) PIC is a tad slower than non-PIC, well... But thanks PIE you can map the executable itself into a random address (ASLR), which makes it more difficult for an attacker to find useful "tools" in the executable image. > > It is a security feature which combines with ASLR to do full address > > space randomization. Yes. Cheers - -- tomás -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlmMEqkACgkQBcgs9XrR2kasngCeI49Xp+FPFo34Uy7FXvro2Vzq +VMAn1QCl0A+qu/5PK9hua7Hp8q8ZJP7 =KyAN -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Pascal Hambourg <pascal@plouf.fr.eu.org> |
|---|---|
| Date | 2017-08-12 13:20 +0200 |
| Message-ID | <udCCu-8pQ-13@gated-at.bofh.it> |
| In reply to | #184975 |
Le 10/08/2017 à 10:00, tomas@tuxteam.de a écrit : > > On Wed, Aug 09, 2017 at 08:22:58PM -0400, Gene Heskett wrote: >> >> Aha, another name for PIC, which I've only been writing code that uses it >> for 32 years. Also known as PCR, for Program Counter Relative. Such >> code can be loaded into memory and executed without any patching. > > Not exactly. PIC is "position independent code". Shared libraries have > been compiled like that for a long time since (especially under 32 bits) > you never knew where was a hole in memory to mmap the library in. > > PIE is "position independent executable": it's about using PIC in the > Executable Sorry, but I fail to see the difference. A shared library is executable, and the "code" in PIC is nothing but executable code, isn't it ?
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2017-08-12 16:10 +0200 |
| Message-ID | <udFgZ-1N3-7@gated-at.bofh.it> |
| In reply to | #185089 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Sat, Aug 12, 2017 at 01:11:43PM +0200, Pascal Hambourg wrote: > Le 10/08/2017 à 10:00, tomas@tuxteam.de a écrit : [...] > >PIE is "position independent executable": it's about using PIC in the > >Executable > > Sorry, but I fail to see the difference. > A shared library is executable, and the "code" in PIC is nothing but > executable code, isn't it ? The difference is in intention (both are ELF these days). /bin/ls is an "executable", /lib/x86_64-linux-gnu/libc.so.6 is a lib (yes, this one has an entry point, you can invoke it from the command line). While enabling PIC for libs has been done for a long time (IIRC the first motivator was limited address space under 32 bit) and always seemed a Good Idea(TM), for the executables I think it's ASLR what brought a motivation with it. But I might be wrong. Cheers - -- tomás -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlmPDAsACgkQBcgs9XrR2kbHewCdH//d0m1s14IIORFrqcGMs2DZ KIwAn0TdaN6+D7uM5ce8EkMMcXvUj2Q6 =sZgI -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2017-08-10 10:00 +0200 |
| Message-ID | <ucQxP-2tn-1@gated-at.bofh.it> |
| In reply to | #184937 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Wed, Aug 09, 2017 at 02:49:06PM +0000, 慕 冬亮 wrote: > > > On 08/09/2017 10:31 AM, Thomas Schmitt wrote: > > Hi, > > > > 慕 冬亮 <mudongliangabcd@hotmail.com> wrote: > >> When does Debian Team, or Security Team decide to enable PIE by default? > > I guess it was one year ago. At least that's the dates one can see on > > https://wiki.debian.org/Hardening/PIEByDefaultTransition > Such a good news for me, a student learning information security. > However, I have a doubt, why does Debian enable PIE by default, other > than stack protector and FORTIFY_SOURCE that are already enabled by > default in the Ubuntu distribution? > > I think stack protector(FORTIFY_SOURCE) has less overhead than PIE. As far as I understand, stack protection and/or FORTIFY_SOURCE are about protecting from buffer overflows. Stack protection sounds pretty generic, in the case of FORTIFY_SOURCE, it's the compiler doing extra compile-time checks (when possible) and inserting extra run-time check code. PIE isn't a security measure in itself -- it just allows such code to be dynamically mapped at any address. But it enables address space layout randomisation [1], which isn't a security measure in itself either, but a *mitigation* technique: if an attacker has already managed to take control of your program counter (e.g. by rewriting a return address... possibly via a stack overflow, see above), you make his/her life harder by not putting (potentially useful) code at a place (s)he knows how to find. It's like putting a chair in a dark room. Of course you should try to make your door and lock as secure as possible. But just in case... > No System Is Safe! exactly :-) Cheers -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlmMERMACgkQBcgs9XrR2kantACfXjHdLt0pWUu3sV6sui/8SB4F J7UAnR0WzXmHw2WETK9UddYeHTjmc1u/ =MhEm -----END PGP SIGNATURE-----
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web