LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-14-2008, 04:24 PM   #1
PlatinumX
Member
 
Registered: May 2008
Location: France
Distribution: Debian / Fedora / Gentoo
Posts: 178

Rep: Reputation: 15
Compilation with SSP (Stack smash protection)


Hi all,

To avoid buffer overflow, i am compiling a software with GCC 4.3 and the Stack Smash Protection flag raised (-fstack-protector).

I would like to be sure SSP was really used when compiling the soft.

Is there a way to verify if a binary is using SSP ?

Thanks
 
Old 11-14-2008, 04:28 PM   #2
estabroo
Senior Member
 
Registered: Jun 2008
Distribution: debian, ubuntu, sidux
Posts: 1,126
Blog Entries: 2

Rep: Reputation: 124Reputation: 124
Easiest way is to look up a tutorial on stack smashing, take their example victim program, compile it with stack protection and follow the tutorial, if the tutorial works then ssp either isn't compiled in or didn't work.
 
Old 11-14-2008, 04:38 PM   #3
PlatinumX
Member
 
Registered: May 2008
Location: France
Distribution: Debian / Fedora / Gentoo
Posts: 178

Original Poster
Rep: Reputation: 15
Yea I could do this.

But my aim is to check for a given program if SSP was enabled.

I can't "guess" this info only whith the binary ?

Thx
 
Old 11-14-2008, 05:57 PM   #4
estabroo
Senior Member
 
Registered: Jun 2008
Distribution: debian, ubuntu, sidux
Posts: 1,126
Blog Entries: 2

Rep: Reputation: 124Reputation: 124
compile it both ways and check the difference with cmp and elf tools like objdump
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Problem compiling BlueZ stack on ARM ( cross compilation from linux x86) shilpates Linux - Wireless Networking 1 08-20-2008 03:02 AM
HLFS glibc-2.5 and ssp Angeliqe Linux From Scratch 2 01-29-2007 01:56 PM
Smashing the stack protection Seniltai Programming 1 04-21-2006 12:12 PM
OpenBSD vs Linux+PaX+SSP+RSBAC jakaro *BSD 3 06-23-2005 07:05 PM
Looking for opinions: Best stack protection for Linux? chort Linux - Security 3 11-10-2004 02:43 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:14 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration