In OpenBSD è stata applicata una ristrutturazione durante l'avvio per sshd

In OpenBSD, a technique for vulnerability exploitation protection has been implemented, based on randomly reconfiguring the sshd executable file at each system boot. Previously, such reconfiguration techniques were applied to the kernel and libraries libc.so, libcrypto.so, and ld.so, and now it will be applied to some executable files as well. This method is also planned to be implemented soon for ntpd and other server applications. The change is already included in the CURRENT branch and will be offered in the OpenBSD 7.3 release.

Reconfiguration makes function offsets in libraries less predictable, complicating the creation of exploits that use Return-Oriented Programming (ROP) techniques. When using ROP, an attacker does not try to place their own code in memory but operates with existing pieces of machine instructions in loaded libraries that end with a return control instruction (typically the ends of library functions). The exploit's operation reduces to constructing a chain of calls of such blocks ('gadgets') to achieve the desired functionality.

Fonte: opennet.ru

Acquista hosting affidabile per siti web con protezione DDoS, server VPS VDS 🔥 Acquista hosting affidabile per siti web con protezione DDoS, server VPS VDS | ProHoster