Re: XP vs Mac OS X



Guy Macon <_see.web.page_@xxxxxxxxxxxxxxxxxx> wrote:

>
>
>
>Bob Monsen wrote:
>
>>Well, you are right about that, but with regards to root attacks, the
>>smaller the kernel, the less likely it is for kernel bugs to allow
>>attacker code to run. That is the most likely means of attack for a
>>network worm, for example, or a file system exploit: get the kernel to
>>run the attacker's code somehow.
>
>...which is why QNX is the most bug-free and hardest to attack OS.

It is also least used. Quite a lot of software runs on it though (I
even got Samba to run on it so I could edit sources in a Windows
machine).

Still, I'm pretty sure QNX will have some security holes in it because
it is optimized for real time processes, not security.

--
Reply to nico@nctdevpuntnl (punt=.)
Bedrijven en winkels vindt U op www.adresboekje.nl
.



Relevant Pages

  • Re: real security - no foreign binaries
    ... The whole point of a buffer-overflow attack ... >> own kernel and libraries using a nice big random number. ...
    (comp.os.linux.security)
  • Re: [opensuse] Kernel Security Issue
    ... just how would my system come under attack by it? ... "Please note that these update channels contain "beta" quality updates, so are not recommended for production use systems. ... Only use the kernel." ... If I have a production machine, ...
    (SuSE)
  • Re: Any working ichsmb(4) platforms out there?
    ... FreeBSD attack.young-alumni.com 7.1-PRERELEASE FreeBSD 7.1-PRERELEASE ... ATTACK amd64 ... Does your kernel include all 3 of the following devices? ... smbus(4) -- adds support for kernel SMBus API framework and interfaces ...
    (freebsd-stable)
  • Re: away
    ... gdb support for these new thread libraries from kernel to userland ... but I am sorry, the attack made to me is very harmful, I feel I can ... not recover from such disaster, working on FreeBSD is no longer fun. ...
    (freebsd-current)
  • Re: thoughts on kernel security issues
    ... separate consoles and you can do the attack 3 times faster). ... You need source code to do ... send the line "unsubscribe linux-kernel" in ...
    (Linux-Kernel)