diff --git a/debian/security-misc.maintscript b/debian/security-misc.maintscript index 59043e5..e046582 100644 --- a/debian/security-misc.maintscript +++ b/debian/security-misc.maintscript @@ -67,3 +67,6 @@ rm_conffile /etc/permission-hardening.d/25_default_whitelist_sudo.conf rm_conffile /etc/permission-hardening.d/25_default_whitelist_unix_chkpwd.conf rm_conffile /etc/permission-hardening.d/25_default_whitelist_virtualbox.conf rm_conffile /etc/permission-hardening.d/30_default.conf + +## repalced with /usr/bin/disabled-miscellaneous-by-security-misc +rm_conffile /usr/bin/disabled-vivid-by-security-misc \ No newline at end of file diff --git a/etc/modprobe.d/30_security-misc_disable.conf b/etc/modprobe.d/30_security-misc_disable.conf index 024a0b1..eda012c 100644 --- a/etc/modprobe.d/30_security-misc_disable.conf +++ b/etc/modprobe.d/30_security-misc_disable.conf @@ -39,7 +39,7 @@ ## https://security.stackexchange.com/questions/119712/methods-root-can-use-to-elevate-itself-to-kernel-mode ## https://github.com/Kicksecure/security-misc/issues/215 ## -#install msr /usr/bin/disabled-msr-by-security-misc +#install msr /usr/bin/disabled-miscellaneous-by-security-misc ## File Systems: ## Disable uncommon file systems to reduce attack surface. @@ -200,7 +200,7 @@ install floppy /bin/true /usr/bin/disabled-miscellaneous-by-security-misc ## https://www.openwall.com/lists/oss-security/2019/11/02/1 ## https://github.com/a13xp0p0v/kconfig-hardened-check/commit/981bd163fa19fccbc5ce5d4182e639d67e484475 ## -install vivid /usr/bin/disabled-vivid-by-security-misc +install vivid /usr/bin/disabled-miscellaneous-by-security-misc ## Thunderbolt: ## Disables Thunderbolt modules to prevent some DMA attacks. diff --git a/usr/bin/disabled-vivid-by-security-misc b/usr/bin/disabled-vivid-by-security-misc deleted file mode 100755 index f2d07b7..0000000 --- a/usr/bin/disabled-vivid-by-security-misc +++ /dev/null @@ -1,10 +0,0 @@ -#!/bin/bash - -## Copyright (C) 2019 - 2024 ENCRYPTED SUPPORT LP -## See the file COPYING for copying conditions. - -## Alerts the user that a kernel module failed to load due to it being blacklisted by default. - -echo "$0: ERROR: This vivid kernel module is disabled by package security-misc by default. See the configuration file /etc/modprobe.d/30_security-misc_disable.conf | args: $@" >&2 - -exit 1