Replace bash file presented for disabling of miscellaneous modules

This commit is contained in:
Raja Grewal 2024-07-15 21:08:45 +10:00
parent 8219a1e257
commit fda3832eaf
No known key found for this signature in database
GPG Key ID: 92CA473C156B64C4
3 changed files with 5 additions and 12 deletions

View File

@ -67,3 +67,6 @@ rm_conffile /etc/permission-hardening.d/25_default_whitelist_sudo.conf
rm_conffile /etc/permission-hardening.d/25_default_whitelist_unix_chkpwd.conf
rm_conffile /etc/permission-hardening.d/25_default_whitelist_virtualbox.conf
rm_conffile /etc/permission-hardening.d/30_default.conf
## repalced with /usr/bin/disabled-miscellaneous-by-security-misc
rm_conffile /usr/bin/disabled-vivid-by-security-misc

View File

@ -39,7 +39,7 @@
## https://security.stackexchange.com/questions/119712/methods-root-can-use-to-elevate-itself-to-kernel-mode
## https://github.com/Kicksecure/security-misc/issues/215
##
#install msr /usr/bin/disabled-msr-by-security-misc
#install msr /usr/bin/disabled-miscellaneous-by-security-misc
## File Systems:
## Disable uncommon file systems to reduce attack surface.
@ -200,7 +200,7 @@ install floppy /bin/true /usr/bin/disabled-miscellaneous-by-security-misc
## https://www.openwall.com/lists/oss-security/2019/11/02/1
## https://github.com/a13xp0p0v/kconfig-hardened-check/commit/981bd163fa19fccbc5ce5d4182e639d67e484475
##
install vivid /usr/bin/disabled-vivid-by-security-misc
install vivid /usr/bin/disabled-miscellaneous-by-security-misc
## Thunderbolt:
## Disables Thunderbolt modules to prevent some DMA attacks.

View File

@ -1,10 +0,0 @@
#!/bin/bash
## Copyright (C) 2019 - 2024 ENCRYPTED SUPPORT LP <adrelanos@whonix.org>
## See the file COPYING for copying conditions.
## Alerts the user that a kernel module failed to load due to it being blacklisted by default.
echo "$0: ERROR: This vivid kernel module is disabled by package security-misc by default. See the configuration file /etc/modprobe.d/30_security-misc_disable.conf | args: $@" >&2
exit 1