Can the kernel be recompiled with the openwall or grsec security patches in place… patching that would limit/prevent buffer overflows?
Recompiling the kernel is allowed. BUT: patches that would limit/prevent buffer overflows are not allowed. Remember that the exercise is about application layer security and not about creating an OS that works around insecure applications. Note however, that all kernel level measures that are active due to our configuration are considered OK.
Related Questions
- Can the kernel be recompiled with the openwall or grsec security patches in place... patching that would limit/prevent buffer overflows?
- Through the application security interface, can our site limit access to application functions, etc., through RACF/ACF2/TOP SECRET?
- Who is responsible for keeping security patches up to date for the Private Servers and pre-installed software?