<p><a href="https://suya.place/users/a1ba" class="u-url mention">@a1ba@suya.place</a> Given a decade of ASLR bypass exploits via dmesg (plagued by pointer leaks) and that 90% of Linux installations use default configurations on servers, I argue that privileged dmesg access is the sane default. Yes, ASLR can be bypassed, but at least you need to do a real hack instead of just reading a no-brainer pointer in dmesg.</p>
Reply