Patrick Schleizer
|
0f86fbd8ce
|
Merge pull request #242 from raja-grewal/ptrace
Disable the usage of `ptrace()` by all processes
|
2024-07-28 15:43:54 -04:00 |
|
Raja Grewal
|
9cabaa1bd1
|
Typo
|
2024-07-28 22:04:30 +10:00 |
|
Raja Grewal
|
d2d024ebe9
|
Typo
|
2024-07-28 22:03:33 +10:00 |
|
Raja Grewal
|
9fbee9fc82
|
Clarify
|
2024-07-28 21:57:25 +10:00 |
|
Raja Grewal
|
1445457626
|
Show details regarding secure_redirects (again)
|
2024-07-27 14:00:30 +10:00 |
|
Raja Grewal
|
73979d4342
|
Link to ptrace() discussion
|
2024-07-27 13:28:59 +10:00 |
|
Raja Grewal
|
1c9f33f906
|
Revert "Disable the usage of ptrace() by all processes"
This reverts commit b04828f858 .
|
2024-07-27 13:24:08 +10:00 |
|
Patrick Schleizer
|
886f6095db
|
Merge pull request #250 from raja-grewal/Panik-Kalm
Add details on "oopes" and kernel panics
|
2024-07-26 11:08:30 -04:00 |
|
Patrick Schleizer
|
e2ae93a957
|
port to safe_echo
|
2024-07-26 10:30:45 -04:00 |
|
Patrick Schleizer
|
8ec23ed712
|
echo does not support end-of-options
|
2024-07-26 10:28:57 -04:00 |
|
Patrick Schleizer
|
6096ed1109
|
comment
|
2024-07-26 10:26:43 -04:00 |
|
Patrick Schleizer
|
ac41d1cfff
|
comment
|
2024-07-26 10:25:59 -04:00 |
|
Patrick Schleizer
|
3b033ceba2
|
shellcheck
|
2024-07-26 10:17:24 -04:00 |
|
Patrick Schleizer
|
04d9ca1ebe
|
use find with safe_echo_nonewline
|
2024-07-26 10:16:20 -04:00 |
|
raja-grewal
|
20454fb811
|
Merge branch 'Kicksecure:master' into blacklist_to_disable
|
2024-07-27 00:09:30 +10:00 |
|
Patrick Schleizer
|
6bbf176e3b
|
consider end-of-options for find
|
2024-07-26 09:33:45 -04:00 |
|
Patrick Schleizer
|
794f6a25fa
|
comment
|
2024-07-26 09:08:29 -04:00 |
|
Patrick Schleizer
|
7e0f1a8701
|
dpkg-statoverride can actually handle '--file-name'.
|
2024-07-26 09:08:04 -04:00 |
|
Patrick Schleizer
|
ee037c01a1
|
Skip file names starting with '--',
because this would be interpreted by dpkg-statoverride as an option.
|
2024-07-26 08:58:44 -04:00 |
|
Patrick Schleizer
|
82d401a7de
|
sanity test
|
2024-07-26 08:52:42 -04:00 |
|
Patrick Schleizer
|
0e661bc688
|
output
|
2024-07-26 08:49:14 -04:00 |
|
Patrick Schleizer
|
d144f68d1a
|
output
|
2024-07-26 08:46:08 -04:00 |
|
Patrick Schleizer
|
05504b9ab2
|
minor
|
2024-07-26 08:40:10 -04:00 |
|
Patrick Schleizer
|
d96c0633d4
|
more use of end of options
|
2024-07-26 08:39:11 -04:00 |
|
Patrick Schleizer
|
8e40c10c31
|
comment
|
2024-07-26 08:31:17 -04:00 |
|
Patrick Schleizer
|
f2c9c2f5d1
|
output
|
2024-07-26 08:26:16 -04:00 |
|
Patrick Schleizer
|
2b40ea75e9
|
cleanup
|
2024-07-26 08:24:23 -04:00 |
|
Patrick Schleizer
|
6f0551b944
|
refactoring
|
2024-07-26 08:23:54 -04:00 |
|
Patrick Schleizer
|
aac450f808
|
refactoring
|
2024-07-26 08:22:04 -04:00 |
|
Patrick Schleizer
|
30f46790a4
|
use end of options whenever possible
|
2024-07-26 08:21:21 -04:00 |
|
Patrick Schleizer
|
95722d6d79
|
use long option name
|
2024-07-26 08:13:33 -04:00 |
|
Patrick Schleizer
|
19f131c742
|
code simplification
https://github.com/Kicksecure/security-misc/pull/251
|
2024-07-26 08:07:08 -04:00 |
|
Patrick Schleizer
|
9694cf0cd1
|
output
|
2024-07-26 07:43:59 -04:00 |
|
Ben Grande
|
652a06c8e9
|
Only print SUID or SGID values when set
|
2024-07-25 12:37:21 +02:00 |
|
Ben Grande
|
3b8a3f9b83
|
Unduplicate stat call
|
2024-07-25 12:20:16 +02:00 |
|
Raja Grewal
|
ed3336694c
|
Provide the option to immediately reboot on a kernel panics
|
2024-07-25 10:28:27 +10:00 |
|
Raja Grewal
|
3926b91dcf
|
Add documentation on sysctl kernel.panic_on_oops=1
|
2024-07-25 10:26:23 +10:00 |
|
Raja Grewal
|
f699eb02a2
|
Set sysctl fs.binfmt_misc.status=0
|
2024-07-25 10:11:33 +10:00 |
|
Patrick Schleizer
|
9231f05891
|
todo
|
2024-07-24 13:31:49 -04:00 |
|
Patrick Schleizer
|
4cc1289e89
|
output
|
2024-07-24 13:30:30 -04:00 |
|
Patrick Schleizer
|
10c73b326f
|
fix delimiter parsing
|
2024-07-24 12:07:26 -04:00 |
|
Patrick Schleizer
|
a16dd8474b
|
sanity test
|
2024-07-24 11:50:30 -04:00 |
|
Patrick Schleizer
|
cc2b335ee6
|
cleanup
|
2024-07-24 11:48:32 -04:00 |
|
Patrick Schleizer
|
6cadc70a96
|
output
|
2024-07-24 11:47:52 -04:00 |
|
Patrick Schleizer
|
cda0d26af7
|
cannot use NULL inside a bash variable
use custom delimiter instead
|
2024-07-24 11:45:13 -04:00 |
|
Patrick Schleizer
|
4a5312b3a9
|
output
|
2024-07-24 11:27:51 -04:00 |
|
Patrick Schleizer
|
3bf1f26c0b
|
downgrade warning of non-existing folders to info
to avoid all users by default getting a warning for expected non-existing folders
|
2024-07-24 11:20:26 -04:00 |
|
Patrick Schleizer
|
151ca659a9
|
output
|
2024-07-24 11:19:15 -04:00 |
|
Patrick Schleizer
|
c9fd2ceb61
|
downgrade warning of non-existing files to info
to avoid all users by default getting a warning for expected non-existing files
|
2024-07-24 11:13:35 -04:00 |
|
Patrick Schleizer
|
721392901b
|
remove duplicate test
|
2024-07-24 11:12:39 -04:00 |
|
Patrick Schleizer
|
9712b5b4e3
|
output
|
2024-07-24 11:12:18 -04:00 |
|
Patrick Schleizer
|
00911df5c1
|
modify call of stat to use NUL delimiter
for more robust string parsing
|
2024-07-24 11:10:56 -04:00 |
|
Patrick Schleizer
|
d536683511
|
local clean_output_prefix clean_output
|
2024-07-24 11:03:28 -04:00 |
|
Patrick Schleizer
|
a6e517736b
|
local stat_output
|
2024-07-24 11:02:25 -04:00 |
|
Patrick Schleizer
|
ced02fb9e0
|
add sanity test for file_name output from stat
|
2024-07-24 11:01:24 -04:00 |
|
Patrick Schleizer
|
b9dfe70a01
|
check first if file_name is empty
|
2024-07-24 10:58:05 -04:00 |
|
Patrick Schleizer
|
1cbda79981
|
check first if array is empty before parsing further
|
2024-07-24 10:57:13 -04:00 |
|
Patrick Schleizer
|
a077ae54ea
|
modify call of stat to use NUL delimiter
for more robust string parsing
|
2024-07-24 10:56:08 -04:00 |
|
Patrick Schleizer
|
7200e9bd8c
|
output
|
2024-07-24 09:15:02 -04:00 |
|
Patrick Schleizer
|
1b6161c2dc
|
Merge remote-tracking branch 'ben-grande/fuzz'
|
2024-07-24 09:13:48 -04:00 |
|
Raja Grewal
|
88c88187f2
|
Re-enable (default) secure_redirects for ICMP redirect messages
|
2024-07-24 17:26:50 +10:00 |
|
Ben Grande
|
8be21b6eff
|
Handle newlines in file names
|
2024-07-23 19:36:12 +02:00 |
|
Ben Grande
|
aa99de68d3
|
Log output with defined levels
|
2024-07-23 18:50:16 +02:00 |
|
Ben Grande
|
06fbcdac1d
|
Prettify log messages
|
2024-07-23 09:55:02 +02:00 |
|
Ben Grande
|
7ee1ea2cc7
|
Unify functions that evaluate commands
|
2024-07-22 17:06:07 +02:00 |
|
Ben Grande
|
9c3566f524
|
Delimit file names with null terminator
|
2024-07-22 16:56:42 +02:00 |
|
Raja Grewal
|
a189956adc
|
Typo
|
2024-07-20 20:11:09 +10:00 |
|
Raja Grewal
|
c4965ed838
|
Disable legacy framebuffer drivers
These were all previously blacklisted for over 2 years.
|
2024-07-20 14:55:10 +10:00 |
|
Patrick Schleizer
|
9f53a0182b
|
undo io_uring related changes
as these should be done in a separate pull request (if apprpriate)
https://github.com/Kicksecure/security-misc/pull/244#issuecomment-2238889062
|
2024-07-19 07:20:59 -04:00 |
|
Raja Grewal
|
13cc1f0986
|
Clarify (future) disabling of io_uring
|
2024-07-18 12:25:00 +10:00 |
|
Raja Grewal
|
6d211faf59
|
Restrict unprivileged user namespaces
|
2024-07-18 11:04:54 +10:00 |
|
Raja Grewal
|
b04828f858
|
Disable the usage of ptrace() by all processes
|
2024-07-18 11:01:41 +10:00 |
|
Patrick Schleizer
|
a2e26f441b
|
spelling
|
2024-07-17 11:04:03 -04:00 |
|
Patrick Schleizer
|
c8be4ac83c
|
comment
|
2024-07-17 10:56:14 -04:00 |
|
Patrick Schleizer
|
24cd70a014
|
spelling
|
2024-07-17 10:55:12 -04:00 |
|
Patrick Schleizer
|
9a387f95e9
|
Merge remote-tracking branch 'raja/miscellaneous'
|
2024-07-17 10:32:26 -04:00 |
|
Raja Grewal
|
4afe257a42
|
minor
|
2024-07-18 00:14:13 +10:00 |
|
Raja Grewal
|
d0a59617f6
|
Add missing Copyright (C) statements
|
2024-07-18 00:13:30 +10:00 |
|
Raja Grewal
|
8f3896c3da
|
Upgrade hyperlinks to HTTPS
|
2024-07-17 23:44:37 +10:00 |
|
Raja Grewal
|
1087387b36
|
Remove obsolete #net.ipv4.tcp_fack=0
|
2024-07-17 23:35:25 +10:00 |
|
Patrick Schleizer
|
df80385289
|
Merge pull request #237 from raja-grewal/intel_pmt
Disable some Intel PMT kernel modules
|
2024-07-17 09:04:18 -04:00 |
|
Patrick Schleizer
|
0b873b765e
|
minor
|
2024-07-17 08:05:27 -04:00 |
|
Patrick Schleizer
|
070bb46a08
|
Merge remote-tracking branch 'raja/sysctl'
|
2024-07-17 08:02:45 -04:00 |
|
Patrick Schleizer
|
6d6e5473f2
|
minor
|
2024-07-17 08:00:24 -04:00 |
|
Patrick Schleizer
|
cf5f0edbb8
|
Merge remote-tracking branch 'raja/sysctl'
|
2024-07-17 07:59:35 -04:00 |
|
Raja Grewal
|
39fd125eb0
|
Provide explanation on the disabling of IPv6 Privacy Extensions
|
2024-07-17 21:44:44 +10:00 |
|
Raja Grewal
|
693b47e623
|
Clarify ICMP redirect acceptance and sending
|
2024-07-17 14:58:30 +10:00 |
|
Raja Grewal
|
824d9b82e5
|
Uncomment redundant disabling of TCP FACK`
|
2024-07-17 00:36:18 +10:00 |
|
Raja Grewal
|
d1119c38b6
|
Apply changes from code review
|
2024-07-17 00:31:23 +10:00 |
|
Patrick Schleizer
|
6e63fc8985
|
Merge remote-tracking branch 'ben-grande/fuzz'
|
2024-07-15 17:14:25 -04:00 |
|
Raja Grewal
|
61941da375
|
Create disabled-intelpmt-by-security-misc
|
2024-07-15 22:38:09 +10:00 |
|
Raja Grewal
|
a8bc1144c3
|
Updated wording of error files for disabled modules
|
2024-07-15 21:10:13 +10:00 |
|
Raja Grewal
|
fda3832eaf
|
Replace bash file presented for disabling of miscellaneous modules
|
2024-07-15 21:08:45 +10:00 |
|
Raja Grewal
|
c52b1a3fd2
|
Create disabled-miscellaneous-by-security-misc
|
2024-07-15 20:58:45 +10:00 |
|
Raja Grewal
|
1c2afc1f25
|
Update presentation of the kernel.printk sysctl
|
2024-07-15 15:01:48 +10:00 |
|
Raja Grewal
|
2b9e174c9d
|
Remove empty lines
|
2024-07-14 16:22:52 +10:00 |
|
Raja Grewal
|
dd1741c4a1
|
Some documentation additions and fixes
|
2024-07-14 13:40:53 +10:00 |
|
Raja Grewal
|
565597c9a2
|
Minor documentation changes and fixes
|
2024-07-14 01:21:24 +10:00 |
|
Raja Grewal
|
2de3a79599
|
Refactor existing sysctl for clarity
|
2024-07-13 22:41:40 +10:00 |
|
Raja Grewal
|
f31dc8aebc
|
Fix error in error script
|
2024-07-12 16:21:03 +10:00 |
|