1.9. Disabling Memory Dumps in the Event of a Crash
Problem
Your application stores potentially sensitive data in memory, and you want to prevent this data from being written to disk if the program crashes, because local attackers might be able to examine a core dump and use that information nefariously.
Solution
On Unix systems, use setrlimit(
)
to
set the RLIMIT_CORE resource to zero, which will
prevent the operating system from leaving behind a core file. On
Windows, it is not possible to disable such behavior, but there is
equally no guarantee that a memory dump will be performed. A
system-wide setting that cannot be altered on a per-application basis
controls what action
Windows takes when an application
crashes.
A Windows feature called Dr. Watson, which is enabled by default, may cause the contents of a process’s address space to be written to disk in the event of a crash. If Microsoft Visual Studio is installed, the settings that normally cause Dr. Watson to run are changed to run the Microsoft Visual Studio debugger instead, and no dump will be generated. Other programs do similar things, so from system to system, there’s no telling what might happen if an application crashes.
Unfortunately, there is no way to prevent memory dumps on a
per-application basis on Windows. The settings for how to handle an
application crash are system-wide, stored in the registry under
HKEY_LOCAL_MACHINE, and they require Administrator access to change them. Even if you’re reasonably certain ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access