Most secure PaX configuration for a binary?
Posted: Sun Jul 20, 2014 5:36 pm
I've been told that enabling EMUTRAMP actually makes PaX security less secure than if it was off. Is that true?
That would mean that -PEMRXS is less secure than -PeMRXS?? And a few of my applications do need -PEmRXS just to work (e.g. browsers).
Note to self:
options:
-p: disable PAGEEXEC -P: enable PAGEEXEC
-e: disable EMUTRAMP -E: enable EMUTRAMP
-m: disable MPROTECT -M: enable MPROTECT
-r: disable RANDMMAP -R: enable RANDMMAP
-x: disable RANDEXEC -X: enable RANDEXEC
-s: disable SEGMEXEC -S: enable SEGMEXEC
Thanks.
That would mean that -PEMRXS is less secure than -PeMRXS?? And a few of my applications do need -PEmRXS just to work (e.g. browsers).
Note to self:
options:
-p: disable PAGEEXEC -P: enable PAGEEXEC
-e: disable EMUTRAMP -E: enable EMUTRAMP
-m: disable MPROTECT -M: enable MPROTECT
-r: disable RANDMMAP -R: enable RANDMMAP
-x: disable RANDEXEC -X: enable RANDEXEC
-s: disable SEGMEXEC -S: enable SEGMEXEC
Thanks.