{"id":185,"date":"2009-05-14T09:18:09","date_gmt":"2009-05-14T17:18:09","guid":{"rendered":"http:\/\/www.outflux.net\/blog\/?p=185"},"modified":"2009-05-15T16:13:17","modified_gmt":"2009-05-16T00:13:17","slug":"nx-emulation-in-ubuntu","status":"publish","type":"post","link":"https:\/\/outflux.net\/blog\/archives\/2009\/05\/14\/nx-emulation-in-ubuntu\/","title":{"rendered":"partial NX emulation in Ubuntu"},"content":{"rendered":"<p>Now available for early testing, <a href=\"http:\/\/www.ubuntu.com\/testing\/karmic\/alpha1\">Ubuntu Karmic Alpha 1<\/a> has a kernel feature I&#8217;ve long wanted in Ubuntu: NX emulation.  Basically, if your hardware <a href=\"http:\/\/www.outflux.net\/blog\/archives\/2008\/11\/21\/make-your-bios-love-security\/\">lacks NX support<\/a>, the kernel will emulate the feature using memory segment limits and ordering.  This was AFAIBT originally developed by PaX, and a similar version (with histories including work by Solar Designer and maybe OpenBSD?) has been carried in RedHat\/Fedora for a while now (under the larger project called &#8220;ExecShield&#8221;, covering multiple protection technologies).<\/p>\n<p>As more and more of the monolithic ExecShield kernel patch has been taken upstream (many thanks to Arjan van de Ven for <a href=\"http:\/\/lkml.org\/lkml\/2005\/1\/27\/56\">pushing<\/a> them), the patch in RedHat has been shrinking.  Recently, <a href=\"http:\/\/www.codemonkey.org.uk\/\">Dave Jones<\/a> split up the <a href=\"http:\/\/www.codemonkey.org.uk\/projects\/execshield\/\">remaining pieces<\/a> into logical chunks small enough that I could actually read it without going cross-eyed.  From this, I ported the <a href=\"https:\/\/lists.ubuntu.com\/archives\/kernel-team\/2009-April\/005666.html\">nx-emulation patches<\/a> to Ubuntu&#8217;s kernel, and now they&#8217;re happily live in Karmic.<\/p>\n<p>So, instead of this:<\/p>\n<blockquote><p><code>$ .\/vulnerable-setuid-program $OVERFLOW_AND_SHELLCODE<br \/>\n# id<br \/>\nuid=0(root) gid=0(root) groups=0(root)<\/code><\/p><\/blockquote>\n<p>We get this:<\/p>\n<blockquote><p><code>$ .\/vulnerable-setuid-program $OVERFLOW_AND_SHELLCODE<br \/>\nSegmentation fault (core dumped)<br \/>\n$ dmesg | tail -n1<br \/>\n[170131.763976] vulnerable-set[16278]: general protection ip:80489c5 sp:bfa3e330 error:0 in vulnerable-setuid-program[8048000+1000]<\/code><\/p><\/blockquote>\n<p>Though, as always, please just use 64bit instead.  :)<\/p>\n<p><strong>Update:<\/strong> gave credit to PaX, thanks for the corrections!<\/p>\n<p style='text-align:left'>&copy; 2009, <a href=\"https:\/\/outflux.net\/blog\/\">Kees Cook<\/a>. This work is licensed under a <a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\">Creative Commons Attribution-ShareAlike 4.0 License<\/a>.<br \/><a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\"><img decoding=\"async\" alt=\"CC BY-SA 4.0\" style=\"border-width:0\" src=\"https:\/\/i.creativecommons.org\/l\/by-sa\/4.0\/88x31.png\" \/><\/a> <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Now available for early testing, Ubuntu Karmic Alpha 1 has a kernel feature I&#8217;ve long wanted in Ubuntu: NX emulation. Basically, if your hardware lacks NX support, the kernel will emulate the feature using memory segment limits and ordering. This was AFAIBT originally developed by PaX, and a similar version (with histories including work by [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,14],"tags":[],"_links":{"self":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/185"}],"collection":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/comments?post=185"}],"version-history":[{"count":8,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/185\/revisions"}],"predecessor-version":[{"id":189,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/185\/revisions\/189"}],"wp:attachment":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/media?parent=185"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/categories?post=185"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/tags?post=185"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}