pids not randomized

Discuss usability issues, general maintenance, and general support issues for a grsecurity-enabled system.

pids not randomized

Postby mr.fox » Sun May 20, 2007 2:26 pm

I have just compiled a 2.6.19.2 kernel with grsecurity 2.1.10.

however, process ids are NOT randomized! in the kernel config menu, there is no option to change this, too.

what am I doing wrong? does this depend on other kernel features, and which?

thanks,
- Dave.
mr.fox
 
Posts: 2
Joined: Sun May 20, 2007 2:20 pm

Postby bplant » Sun May 20, 2007 6:23 pm

Hi Dave,

It's mentioned in the release notes: http://grsecurity.net/news.php#grsec2110

Cheers,

Brad
bplant
 
Posts: 73
Joined: Sat May 28, 2005 10:36 pm

Postby mr.fox » Sun May 20, 2007 6:41 pm

d'oh! rtfm :)

just out of curiosity, why is this suddenly considered to "not provide additional security"? from earlier versions:

"This is extremely effective along
with the /proc restrictions to disallow an attacker from guessing
pids of daemons, etc. PIDs are also used in some cases as part
of a naming system for temporary files, so this option would keep
those filenames from being predicted as well."

thanks.
- Dave
mr.fox
 
Posts: 2
Joined: Sun May 20, 2007 2:20 pm

Postby jj2 » Mon May 21, 2007 8:21 am

I think mostly it was to provides better salt to apps that use getpid as seeding their random number generatr.
jj2
 
Posts: 2
Joined: Mon May 21, 2007 8:10 am


Return to grsecurity support