GithubHelp home page GithubHelp logo

mprotect_demo's Introduction

mprotect demo

This is a simple demo of using mprotect along with some ELF section hackery on BSD / Linux in order to allow a program to disable functions at runtime by removing the execute bit from their segments. This requires some mad hackery and is probably not that portable. Currently, this relies on the linker placing two sections defined one right after another in sections that are one right after the other as well as the runtime loader respecting these placements.

This is a proof of concept. When used in conjunction with OpenBSD pledge or Linux seccomp to prevent mprotect from ever adding back execute bits to segments in memory, this allows a program to disable functionality at runtime.

This is useful during privilege separation. The process can not only shed privileges via chroot, pledge, unveil, or loading a seccomp policy, but it can also shed functions it will never call. This shedding of functions can happen at any time permissible by the OS and runtime. So, for instance, config parsing functions or API calls to other processes can be shed once they are no longer needed. Any code paths that would call these function groups would cause the application to crash instead of calling them, reducing the ability for a remote attacker to "trick" software into calling functions it should not call.

mprotect_demo's People

Contributors

nanolith avatar

Watchers

 avatar  avatar  avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.