X-Original-To: alpine-devel@lists.alpinelinux.org Delivered-To: alpine-devel@mail.alpinelinux.org Received: from out1-smtp.messagingengine.com (out1-smtp.messagingengine.com [66.111.4.25]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by mail.alpinelinux.org (Postfix) with ESMTPS id 1E897DC1A82 for ; Thu, 12 Apr 2012 03:19:44 +0000 (UTC) Received: from compute1.internal (compute1.nyi.mail.srv.osa [10.202.2.41]) by gateway1.nyi.mail.srv.osa (Postfix) with ESMTP id D5ACF2098E for ; Wed, 11 Apr 2012 23:19:43 -0400 (EDT) Received: from web4.nyi.mail.srv.osa ([10.202.2.214]) by compute1.internal (MEProxy); Wed, 11 Apr 2012 23:19:43 -0400 DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d= messagingengine.com; h=message-id:from:to:mime-version :content-transfer-encoding:content-type:in-reply-to:references :subject:date; s=smtpout; bh=Uiv5WlAzsHM7sX3EjurOMwhDtyg=; b=l+4 m2/urV61797zJspgraUgPy/z3bI9T0AkRz5GJFMEhEaKxYDEPSwJI1VDRsV2RdWh KXb5Ql20bPM7IiZczPQU47UlQtKQYsdt2AfjgE0elfjxLkAFcAKpBIgXAtx9nrE5 idbvbOrQwdZJZs5aGXBn5y5F/uWWOXgVZ9xY8f+I= Received: by web4.nyi.mail.srv.osa (Postfix, from userid 99) id AC5CF3C1F19; Wed, 11 Apr 2012 23:19:43 -0400 (EDT) Message-Id: <1334200783.28154.140661061298453.0B5FBB22@webmail.messagingengine.com> X-Sasl-Enc: KO8V/aXs+w39OhHuSS/GkhMQtt5b7GvQB6AELYaYlMrS 1334200783 From: Dubiousjim To: alpine-devel@lists.alpinelinux.org X-Mailinglist: alpine-devel Precedence: list List-Id: Alpine Development List-Unsubscribe: List-Post: List-Help: List-Subscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Type: text/plain X-Mailer: MessagingEngine.com Webmail Interface In-Reply-To: References: <965117.94628.bm@smtp142.mail.ukl.yahoo.com> <148752.52050.bm@smtp133.mail.ukl.yahoo.com> Subject: Re: [alpine-devel] [announce] Sonnet GNU/Linux (somewhat derivative of Alpine) Date: Wed, 11 Apr 2012 23:19:43 -0400 On Wed, Apr 11, 2012, at 11:27 PM, William Pitcock wrote: > > This is false. The fact that the distribution is compiled with PIE is > why many known exploits fail. The fact that binaries are compiled > with PIE allows the ASLR code (either in Linux itself or provided by > PaX) to randomize specific segment addresses in a binary. ASLR is the > reason why ret2libc attacks are not successful. > ... Thank you for this detailed explanation. -- dubiousjim@gmail.com --- Unsubscribe: alpine-devel+unsubscribe@lists.alpinelinux.org Help: alpine-devel+help@lists.alpinelinux.org ---