{"id":18,"date":"2012-11-28T14:16:31","date_gmt":"2012-11-28T01:16:31","guid":{"rendered":"http:\/\/micro.muppetz.com\/blog\/?p=18"},"modified":"2015-02-04T14:37:44","modified_gmt":"2015-02-04T01:37:44","slug":"paxtest-grsecurity-vs-vanilla-kernel","status":"publish","type":"post","link":"https:\/\/micro.muppetz.com\/blog\/2012\/11\/28\/paxtest-grsecurity-vs-vanilla-kernel\/","title":{"rendered":"Paxtest: grsecurity vs vanilla kernel"},"content":{"rendered":"<p><span style=\"text-decoration: underline;\">Vanilla Kernel<\/span><br \/>\n<code><br \/>\ntimh@Jumphost-Lab:~$ paxtest blackhat<br \/>\nPaXtest - Copyright(c) 2003,2004 by Peter Busser &lt;peter@adamantix.org&gt; Released under the GNU Public Licence version 2 or later<br \/>\nWriting output to \/home\/timh\/paxtest.log<br \/>\nIt may take a while for the tests to complete<br \/>\nTest results:<br \/>\nPaXtest - Copyright(c) 2003,2004 by Peter Busser &lt;peter@adamantix.org&gt; Released under the GNU Public Licence version 2 or later<br \/>\nMode: Blackhat<br \/>\nLinux Jumphost-Lab 3.2.0-29-generic 46-Ubuntu SMP Fri Jul 27 17:03:23 UTC 2012 x86_64 x86_64 x86_64 GNU\/Linux<br \/>\nExecutable anonymous mapping : Killed<br \/>\nExecutable bss : Killed<br \/>\nExecutable data : Killed<br \/>\nExecutable heap : Killed<br \/>\nExecutable stack : Killed<br \/>\nExecutable shared library bss : Killed<br \/>\nExecutable shared library data : Killed<br \/>\nExecutable anonymous mapping (mprotect) : Vulnerable<br \/>\nExecutable bss (mprotect) : Vulnerable<br \/>\nExecutable data (mprotect) : Vulnerable<br \/>\nExecutable heap (mprotect) : Vulnerable<br \/>\nExecutable stack (mprotect) : Vulnerable<br \/>\nExecutable shared library bss (mprotect) : Vulnerable<br \/>\nExecutable shared library data (mprotect): Vulnerable<br \/>\nWritable text segments : Vulnerable<br \/>\nAnonymous mapping randomisation test : 9 bits (guessed)<br \/>\nHeap randomisation test (ET_EXEC) : 14 bits (guessed)<br \/>\nHeap randomisation test (PIE) : 16 bits (guessed)<br \/>\nMain executable randomisation (ET_EXEC) : No randomisation<br \/>\nMain executable randomisation (PIE) : 8 bits (guessed)<br \/>\nShared library randomisation test : 10 bits (guessed)<br \/>\nStack randomisation test (SEGMEXEC) : 19 bits (guessed)<br \/>\nStack randomisation test (PAGEEXEC) : 19 bits (guessed)<br \/>\nReturn to function (strcpy) : Vulnerable<br \/>\nReturn to function (memcpy) : Killed<br \/>\nReturn to function (strcpy, PIE) : Vulnerable<br \/>\nReturn to function (memcpy, PIE) : Killed<br \/>\nGrsecurity\/PaX hardened kernel<br \/>\n<\/code><br \/>\n<span style=\"text-decoration: underline;\">Grsecurity Enabled Kernel<\/span><br \/>\n<code><br \/>\ntim@beaker ~&gt; paxtest blackhat<br \/>\nPaXtest - Copyright(c) 2003,2004 by Peter Busser &lt;peter@adamantix.org&gt; Released under the GNU Public Licence version 2 or later<br \/>\nWriting output to paxtest.log<br \/>\nIt may take a while for the tests to complete<br \/>\nTest results:<br \/>\nPaXtest - Copyright(c) 2003,2004 by Peter Busser &lt;peter@adamantix.org&gt; Released under the GNU Public Licence version 2 or later<br \/>\nMode: blackhat<br \/>\nLinux beaker 3.6.8-grsec 1 SMP Wed Nov 28 09:30:28 NZDT 2012 i686 GNU\/Linux<br \/>\nExecutable anonymous mapping : Killed<br \/>\nExecutable bss : Killed<br \/>\nExecutable data : Killed<br \/>\nExecutable heap : Killed<br \/>\nExecutable stack : Killed<br \/>\nExecutable anonymous mapping (mprotect) : Killed<br \/>\nExecutable bss (mprotect) : Killed<br \/>\nExecutable data (mprotect) : Killed<br \/>\nExecutable heap (mprotect) : Killed<br \/>\nExecutable shared library bss (mprotect) : Killed<br \/>\nExecutable shared library data (mprotect): Killed<br \/>\nExecutable stack (mprotect) : Killed<br \/>\nAnonymous mapping randomisation test : 18 bits (guessed)<br \/>\nHeap randomisation test (ET_EXEC) : 22 bits (guessed)<br \/>\nHeap randomisation test (ET_DYN) : 24 bits (guessed)<br \/>\nMain executable randomisation (ET_EXEC) : 18 bits (guessed)<br \/>\nMain executable randomisation (ET_DYN) : 18 bits (guessed)<br \/>\nShared library randomisation test : 18 bits (guessed)<br \/>\nStack randomisation test (SEGMEXEC) : 24 bits (guessed)<br \/>\nStack randomisation test (PAGEEXEC) : 24 bits (guessed)<br \/>\nReturn to function (strcpy) : Vulnerable<br \/>\nReturn to function (strcpy, RANDEXEC) : Vulnerable<br \/>\nReturn to function (memcpy) : Vulnerable<br \/>\nReturn to function (memcpy, RANDEXEC) : Vulnerable<br \/>\nExecutable shared library bss : Killed<br \/>\nExecutable shared library data : Killed<br \/>\nWritable text segments : Killed<br \/>\n<\/code><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Vanilla Kernel timh@Jumphost-Lab:~$ paxtest blackhat PaXtest &#8211; Copyright(c) 2003,2004 by Peter Busser &lt;peter@adamantix.org&gt; Released under the GNU Public Licence version 2 or later Writing output to \/home\/timh\/paxtest.log It may take a while for the tests to complete Test results: PaXtest &#8211; Copyright(c) 2003,2004 by Peter Busser &lt;peter@adamantix.org&gt; Released under the GNU Public Licence version 2 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[17,18,10],"tags":[19,21,20],"class_list":["post-18","post","type-post","status-publish","format-standard","hentry","category-grsecurity","category-security","category-technical","tag-grsec","tag-linux","tag-security"],"_links":{"self":[{"href":"https:\/\/micro.muppetz.com\/blog\/wp-json\/wp\/v2\/posts\/18","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/micro.muppetz.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/micro.muppetz.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/micro.muppetz.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/micro.muppetz.com\/blog\/wp-json\/wp\/v2\/comments?post=18"}],"version-history":[{"count":3,"href":"https:\/\/micro.muppetz.com\/blog\/wp-json\/wp\/v2\/posts\/18\/revisions"}],"predecessor-version":[{"id":115,"href":"https:\/\/micro.muppetz.com\/blog\/wp-json\/wp\/v2\/posts\/18\/revisions\/115"}],"wp:attachment":[{"href":"https:\/\/micro.muppetz.com\/blog\/wp-json\/wp\/v2\/media?parent=18"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/micro.muppetz.com\/blog\/wp-json\/wp\/v2\/categories?post=18"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/micro.muppetz.com\/blog\/wp-json\/wp\/v2\/tags?post=18"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}