no longer disable MSR by default

fixes https://github.com/Kicksecure/security-misc/issues/215
This commit is contained in:
Patrick Schleizer
2024-04-01 02:55:59 -04:00
parent d9ac01ba5c
commit 7dba3fb7be
2 changed files with 2 additions and 11 deletions

View File

@ -33,7 +33,8 @@ install video1394 /usr/bin/disabled-firewire-by-security-misc
## Disable CPU MSRs as they can be abused to write to arbitrary memory.
## https://security.stackexchange.com/questions/119712/methods-root-can-use-to-elevate-itself-to-kernel-mode
install msr /usr/bin/disabled-msr-by-security-misc
## https://github.com/Kicksecure/security-misc/issues/215
#install msr /usr/bin/disabled-msr-by-security-misc
## Disables unneeded network protocols that will likely not be used as these may have unknown vulnerabilties.
## Credit to Tails (https://tails.boum.org/blueprint/blacklist_modules/) for some of these.