| grsecurity is a set of security patches for Linux 2.4 that contain all the
features of Openwall and HAP-Linux, among many other patches for 2.2, and
other OS's. It features the Openwall non-executable stack, PaX, the
Oblivion ACL system, /proc restrictions, chroot restrictions, linking and
FIFO restrictions, exec and set*id logging, secure file descriptors,
trusted path execution, randomized IP IDs, randomized PIDs, randomized TCP
source ports, altered ping ids, randomized TTL, better IP stack randomness,
socket restrictions, sysctl support on nearly all options, secure keymap
loading, stealth networking enhancements, signal logging, failed fork
logging, time change logging, and others. |