CC equivalent of security related switchs

Hi,
Are there any compiler or linker options that perform similar to:
1) Buffer overflow detection (Microsoft's /GS and GNU's -fstack-protector)
2) Prevent data execution (Microsoft's /NXCOMPAT)
3) Position independent executables ( Microsoft's /DYNAMICBASE and GNU's -fpie)
I'm using Solaris Studio 12.2 and not seeing anything in the compiler's documentation. Are there any recommendations hardening executables during the build process? Thanks for any help.
Peter

Hi,
These might be what you're after:
1) -xcheck=stkovf
You should look at using using discover for memory access error detection, the stack overflow checking only checks for running out of stack space, not errors in accessing data held on the stack.
2) -M /usr/lib/ld/map.noexdata
This is a linker mapfile that makes the data segment non-executable.
3) -xcode=pic32
Generates 32-bit position independent code.
HTH,
Darryl.

Similar Messages

  • Can we set up a forum for Security related issues?

    I know many of us think security is a Windows related issue, but from time to time there are security issues that may come up. I had a question so I looked and couldn't find a forum, so I posted in one of the OS X 10.6 sub forums.
    Thanks!

    I am a co-founder of Calendar of Updates http://www.calendarofupdates.com/updates/index.php?act=idx This is a site that is primarily a Windows based security forum (I switched about 4-5 years ago). Over the years, I've tried to grow the Mac side of our forum, but, as you may know, there is little or no interest in security within the Mac community. For many, the feel security is a Windows issue.
    It's a free site, so don't think I have a vested interest in growing the membership, I'm not an owner, either.
    I just created an *Apple OS X Security Issues* forum http://www.calendarofupdates.com/updates/index.php?showforum=209
    Right now it's an empty forum since it was created 10 minutes ago. Please feel free to join the forum and share security related issues and questions.
    I am not aware of any other forums that deal with OS X security issues
    exclusively, so this forum could be a good place to bookmark and visit from time to time.

  • Security related issues

    Hi everybody,
    We know that weblogic stores all its configuration
    parameters in an xml file,including the userid and password for the database
    in clear text form .
    I want to know whether it is a security flaw?
    Is there a way to encrypt the file contents,so that the userid and password
    will not be in clear text form.
    Any suggestions to increase the security on the config file by appliying os
    restriction or by any third party tool will be helpful.
    Thanks in advance
    prashant

    I am a co-founder of Calendar of Updates http://www.calendarofupdates.com/updates/index.php?act=idx This is a site that is primarily a Windows based security forum (I switched about 4-5 years ago). Over the years, I've tried to grow the Mac side of our forum, but, as you may know, there is little or no interest in security within the Mac community. For many, the feel security is a Windows issue.
    It's a free site, so don't think I have a vested interest in growing the membership, I'm not an owner, either.
    I just created an *Apple OS X Security Issues* forum http://www.calendarofupdates.com/updates/index.php?showforum=209
    Right now it's an empty forum since it was created 10 minutes ago. Please feel free to join the forum and share security related issues and questions.
    I am not aware of any other forums that deal with OS X security issues
    exclusively, so this forum could be a good place to bookmark and visit from time to time.

  • Study security related exception handling in Java

    Hi all,
    I am required to do an indepth study on security-related exception handling in Java, their Pluses and minuses... Can ppl suggest me places where I can get a kick start? Any resource that u know can help me out?
    I appreciate ur help in this regard...FYI, I am a grad student and I am doing this as a part of my course-work...I am writing up a report on this...
    Thanx a bunch, in advance for ur help ppl..

    Take a look at the JAAS API and docs.
    - Saish

  • Security related information in SOAP thruough BPEL

    Hi all,
    How to pass the security related information in SOAP(UsernameToken) in BPEL
    thanks
    kalyan

    You can also add the username and password as properties to the invoke .
    open the bpel.xml of your bpel process and the below properties where your partner link is defined
    <property name="wsseHeaders">credentials</property>
    <property name="wsseUsername">YOUR USER</property>
    <property name="wssePassword">YOUR PASSWORD</property>
    As an example check this :
    <partnerLinkBinding name="PartnerLink_1">
    <property name="wsdlLocation">DMSBODServiceRef.wsdl</property>
    <property name="wsseHeaders">credentials</property>
    <property name="wsseUsername">marattu</property>
    <property name="wssePassword">wipro@143</property>
    </partnerLinkBinding>

  • Need BW Security related help

    Hi all
    This is my first BW security related project. This project has 100 Bex reports in the system.
    The client (lets say ABC) has sold one of its subsidiaries to another company (XYZ). Client ABC wants to be able to give access to their BW system and reports to employees of company XYZ. However, they want to make sure the XYZ employees only access :
    1) Specific reports
    2) For the Bex reports they have access to, they should only be able to run those for their division
    3) there are few BOBJ reports(Webi, CR) as well that need to be secured as well
    Can anyone guide me on how to go about delivering this requirement. ALso, what technical skill resources should I look for so I can deliver this requirements.
    All inputs welcome.
    Anya

    Hi Anya,
        Once you have the security on groups assigned in BW, you can import it in the CMC, using the Admin/Authtentic/SAP/Import Func
    And then assign the users and groups each Webi report.
    Regards.

  • HT5312 a question about the  security-related emails

    Excuse me.ive forgot my security questions and answers.and what was worse my yahoo e-mail(which is the security-related emails ) has been closed few days ago.could u help me?

    The Three Best Alternatives for Security Questions and Rescue Mail
         1.  Send Apple an email request at: Apple - Support - iTunes Store - Contact Us.
         2.  Call Apple Support in your country: Customer Service: Contact Apple support.
         3.  Rescue email address and how to reset Apple ID security questions.
    A substitute for using the security questions is to use 2-step verification:
    Two-step verification FAQ Get answers to frequently asked questions about two-step verification for Apple ID.

  • Reporting security-related stack overflow issue

    How should I report a potentially security-related stack overflow issue that I encountered that lead to a QuickTimePlayer crash?

    The most certain way to report a true bug (as opposed to a comment or feature request) is to sign up as an Apple Developer - the online membership is free - and report the bug through the bug reporter.
    Otherwise, report it through the QuickTime Feedback page.
    Regards.

  • "default interface" equivalent for SG300/500 switches?

    Can anyone tell me if there is an equivalent CLI command to reset an interface configuration to default?
    In IOS it is "default interface <interface>" which removes all configuration from that switch port. I don't seem to be able to find the same in the SG series CLI.
    Thanks,
    Rob

    Hello Rob,
    There isn't an equivalent command on the SG series switches, but I will be bringing it up as a feature request, because it would be quite useful.
    Until then the only way to reset a port would be to use all of the no versions of the commands, which I know can be a bit of a pain.
    Thank you for choosing Cisco,
    Christopher Ebert - Advanced Network Support Engineer
    Cisco Small Business Support Center
    *please rate helpful posts*

  • Security related login credentials

    Dear Experts,
    Right now we are sending some financial data (vendor payment data)  from R/3 to Bank using XI middleware. Here  FI User will send data from R/3 to XI and from SAP XI to bank. The FI user password can be changed by BASIS people.   Here for the security  point of view and finance information regard is there any way that we can incorparate a secured password functionality (or) role which cannot be controlled by Basis people. if so could anyone please guide me in this regard ..if not any alternative in this regard.
    Many thanks in advance,
    Balu

    For the password aspect, you can consider using trusted RFC for the internal connection and then encrypt the data being sent to the bank. In the trusted RFC case, you control the access via authorizations in the target system and not a password in the source.
    Which leads into the second aspect... if your basis folks are not responsible for any role maintenance (e.g. in production...) you can switch their access to display for user and role maintenance.
    Of course, you will meet some resistance when doing this...  
    My recommendation would be to compensate the "anything can happen and basis always has to solve it..." scenarios with an emergency user procedure. There are a number of cool and less cool ways of going about this so that during "normal" operations the access to roles is restricted.
    Cheers,
    Julius
    ps: Do not close this thread by just posting "s". The comment field is not mandatory! I deleted some of your recent posts of this type and there are some nasty mails in your inbox which the system sends automatically. Please read them.
    Edited by: Julius Bussche on Nov 2, 2009 10:12 PM

  • Secure L2 Switch

    Topology
    2 F.W.s modules on cluster mode connected to 2 cat2950 switch (not support SSH)
    The policy here is not give an IP address to the switchs on behalf of security (by cisco recommend of allowind only SSH sessions).
    1. Is it popular not to give an IP add. for security reason.
    2. Do I have to change the Switchs to those wich support SSH.

    You will cause yourself difficulties while your switches cannot be managed over the network.
    A compromising solution could be to install a separate management vlan. IP's for the 2950's could be assigned in this range and you could even set this up as an isolated vlan.
    Basic idea is to have management traffic and user traffic both in a separate vlan. This will not offer security in the case of someone sniffing on the networkcable but as you know, rule 1 in security is to disallow/disable physical acces to your equipment and cabling routes. When you can control physical access, this method is more viable (less $$) than changing to switches with SSH support.
    Regards,
    Leo

  • Equivalent of security sync?

    On EAS 11.1.2.1 or MaxL, we cannot find the refresh security from shared services option anymore.
    What is the equivalent of that statement?

    There is no equivelent for 11.1.2.1 as the Security methods were updated (no more Open LDAP) so Syncing is no longer necessary. As soon as users are added, they are effective

  • XML.sendAndLoad - (Security-related) Error Opening URL

    Hi All,
    I know this is a common problem (I've searched), but I'm
    hoping you can help me out.
    1. What my Application Does
    My Flash app uses XML.sendAndLoad() to communicate with a
    Java Servlet on the same domain, in the same webapp.
    2. What happens when I run it on my (developer) machine
    It works.
    I connect to a url "
    http://localhost:8080/webapp1/servlet/FlashServlet"
    perfectly and pass around XML between Flash and Java
    3. What Happens on the Real Machine
    The Real Machines equivalent URL is
    http://int-tzn:8101/webapp1/servlet/FlashServlet
    The XML.sendAndLoad() cannot connect, with a "Error Opening
    URL" error.
    4. What I've Tried
    4.1. Using a
    crossdomain.xml on Real Machine
    (not sure if I've got in correct place, but i
    can see it at
    http://int-tzn:8101/crossdomain.xml
    4.2. Tried a StandAlone (Projector) WITH Network Access
    4.3. Tried using
    LocalContentUpdater to confirm and set
    network access
    4.4. Have set in my ActionScript :
    System.security.allowDomain("*");
    Please help.
    This needs to go into a large Production Environment in 2
    days and there are large amounts of money behind it.
    Thanks in advance.
    - Laven Pillay

    OK the deal is:
    When using TLF, a user visiting your webpage will download the TLF's SWZ file, if the user already has that file it will be downloaded from the adobe site, if the adobe site is down then it will search the .swz from where the website is hosted on.
    Have a read here:
    http://help.adobe.com/en_US/flash/cs/using/WSb03e830bd6f770ee-4b0db644124bbdb363d-8000.htm l#WSb03e830bd6f770ee72b69dc71257a25aa72-8000

  • Security Related

    Hi,
    We have developed one Portal based site using Weblogic Portal Server which comes
    wth Weblogic Platform 7.0.
    Now It is running absolutely fine.But we have used its default RDBMS Based realm.That
    means all user,group etc related information is being stored into database.
    But we have got a different requirement.
    We have pre-existing LDAP server as user repository holding the user credentials.
    Requirement is such that we want to authenticate the portal users against this
    LDAP server but authorization through its (portal servers') own RDBMS repository.
    This LDAP repository can not be used by portal server for entire user management.
    So Can we configure the portal server such a way that it will do
    1. Authentication using company database which is LDAP store and
    2. Authorization/Access Control/Personalization using its RDBMS
    If not so, then how to go about to achieve the required functionality.
    As per our understanding of the protal servers' LDAP support it can use the LDAP
    to provide the complete security i.e. authentication/authorization/personalization
    but not for partial security support as we require.
    Thanks in advance for any suggestions.
    Pavitra

    Hi
    I believe this is possible though i havent done it.
    The new security framework does have separate providers for authentication and
    authorization
    The samples show each provider reading from a different properties file(i.e. different
    sources) so you can authenticate from ldap and authorize from rdbms
    The problem i believe you will face is that the old rdbmsrealm can run only in
    compatibility mode so you can either use rdbmsrealm or the new features
    So you can either
    1. Rewrite the rdbmsrealm into an mbean so that it works as 7.0 security provider(someone
    has posted the steps in this newsgroup)
    or
    2. Modify methods like RDBMSUser.authenticate(from the sample)
    so that it authenticates agains LDAP but authorizes against the database.
    Of Course you will have to keep the users in synch(i.e. if there is a user created
    in the ldap, there must be a user in the rdbms for the foreign key relationships)
    you may need to modify the realm.creatUser.
    HTH
    deepak
    "Pavitra" <[email protected]> wrote:
    >
    Hi,
    We have developed one Portal based site using Weblogic Portal Server
    which comes
    wth Weblogic Platform 7.0.
    Now It is running absolutely fine.But we have used its default RDBMS
    Based realm.That
    means all user,group etc related information is being stored into database.
    But we have got a different requirement.
    We have pre-existing LDAP server as user repository holding the user
    credentials.
    Requirement is such that we want to authenticate the portal users against
    this
    LDAP server but authorization through its (portal servers') own RDBMS
    repository.
    This LDAP repository can not be used by portal server for entire user
    management.
    So Can we configure the portal server such a way that it will do
    1. Authentication using company database which is LDAP store and
    2. Authorization/Access Control/Personalization using its RDBMS
    If not so, then how to go about to achieve the required functionality.
    As per our understanding of the protal servers' LDAP support it can use
    the LDAP
    to provide the complete security i.e. authentication/authorization/personalization
    but not for partial security support as we require.
    Thanks in advance for any suggestions.
    Pavitra

  • Sap CRM 2007 Security related issue

    Hi All,
    I am working on SAP CRM 2007 security.
    I have scenario, which we are trying to fix.
    There are two users A and B.
    A is assigned to role X
    B is assigned to role y
    Business Partner 123 is created for user A
    Business Partner 456 is created for user B
    These Business Partners are assigned to Authorization Groups.
    See below:
    1)Authorization Group (LK01) is assigned to Business Partner --123.
    2) Authorization Group (LK02) is assigned to Business Partner --456
    3) Authorization groups LK01 is assigin to user A in PFCG role X
    4) Authorization groups LK02 is assigin to user B in PFCG role Y
    a) User A assigned with PFCG role X>Authorization Group (LK01)>BP 123.
    b) User B assigned with PFCG role Y>Authorization Group (LK02)>BP 456.
    Note:
    1) Authorization Groups are assigned to BPs under the Control tab.
    2) These Auth Groups are assigned in Authorization Object in PFCG role.
    Now, USER 'A' should not be able to work under the BP 456 as this BP is assigned to authorization group LK02.
    The issue is when we open the WEB UI and login with user A role X, He can search for the BP 456 assigned to Auth Group LK02.
    User A can open the Interaction History and edit the Service Order created using the BP 456.
    He can Edit the following in Service Order details:
    1) General Data Status (from created to complete), Contact person, Sale Rep name.
    2) Organization Data like Sales Office, Sales Org Unit, Distribution Channel
    3) Business Partner.
    However, one good thing is he cannot edit the Account details like Account ID, House No, Employee Resposible, the message he get is "No authorization to change partner with authorization group"  which is a
    good thing.
    I have tried to be precise, please let me know if you require more information.
    Regards,
    Dave.

    I suggest the following:
    Please, check whether the system works if you activate the implementation BUPA_F4_AUGRP.
    In addition check the notes 559662, 674869 and 782927. Maybe the notes are already implemented but you can try then the implementation of the BADI (SE19). It should resolve your issue.
    I have implemented this Badi solution before, and after activation; the search help ; nor search result list did NOT show any Business partners anymore that had an authorization group I was not allowed to see.
    kind regards
    Davy Pelssers
    SAP CRM/Security consultant

Maybe you are looking for

  • Illustrator CC 64 bit crashes after a few seconds of being open (Win 8.1 64bit)

    After following all related issues of others online, nothing has worked to solved this mystery. Ai CC 64bit crashes after a few seconds of being open. I am running Win 8.1 64bit. All other Adobe CC apps work. I have installed and re-installed countle

  • "move" command doesn't work in case of files on network

    I setup a theWatchFolder fold on network as Watch Folder. This works like when the folder on network gets a file, I'm notified via email and the file should move from watch folder (which is on network) to theDestinationFolder (which is also on anothe

  • HT3702 How do I get refunded for a purchase

    I have recently purchased a Tom Tom by mistake as I already have this app can I be refunded many thanks allyg28

  • How do I recover /lib in Solaris 10

    I am running a SunOS Release 5.10 Version Generic_120011-14 64-bit machine. I too (similar to an older post) did rm -rf /lib accidentally, any chance to recover or fix the issue? Already tried mounting the disk and "tar"ing and pipeline copying the f

  • Problem Deploying Ears in Weblogic LC ES 8.2.1

    OK .. does anyone else find the installation under WL 10. cumbersome?<br /><br />So I get all the way to the point in installation where I am in Configuration Manager and deploying the adobe-contentservices.ear and the installation throws the followi