encrypted executables
Joerg Sonnenberger
joerg at britannica.bec.de
Thu Feb 21 03:19:41 UTC 2008
On Wed, Feb 20, 2008 at 09:39:03PM -0500, ari edelkind wrote:
> Mind you, it's true that disabling core dumps with a resource limit
> doesn't keep one from creating a core image using gcore, but since gcore
> generally must either attach to a process using ptrace() or access
> mapped code segments in the original binary (depending on the
> implementation), it won't help in such a case, either.
What prevents me from patching the kernel (!) to just ignore the
resource limit? Nothing.
Joerg
More information about the freebsd-hackers
mailing list