Commit Graph

258 Commits

Author SHA1 Message Date
3558a9949f Enable APT seccomp sandboxing.
Thanks to @torjunkie for the suggestion!

https://forums.whonix.org/t/apt-seccomp-bpf-sandboxing/7702
2019-07-07 09:37:25 +00:00
46409be8b6 Use install instead of blacklist 2019-07-04 14:25:28 +00:00
eb7eaffba1 Blacklist n-hdlc 2019-07-04 14:24:44 +00:00
93c0821054 config-package-dev displace files for change umask
https://forums.whonix.org/t/change-default-umask/7416
2019-07-01 13:35:45 +00:00
a73f0566e9 change default umask to 006
session optional  pam_umask.so usergroups

https://forums.whonix.org/t/change-default-umask/7416/17
2019-07-01 13:25:23 +00:00
41b61e3277 revert to Debian buster original 2019-07-01 13:24:29 +00:00
eedeaa0e7f Update common-session-noninteractive 2019-06-30 13:12:59 +00:00
a9af85f585 Update common-session 2019-06-30 13:12:16 +00:00
1e1d29cfde Create common-session-noninteractive 2019-06-30 13:11:31 +00:00
501901f7c0 Change default umask to 006 2019-06-30 13:10:54 +00:00
09a5c27f47 Create common-session 2019-06-30 13:10:29 +00:00
a319333493 Create login.defs 2019-06-30 13:09:51 +00:00
230ef34db4 Create disable-coredumps.conf 2019-06-30 00:19:04 +00:00
1bf802f846 Create coredumps.conf 2019-06-30 00:16:50 +00:00
f040081a59 Prevent setuid processes from creating coredumps. 2019-06-30 00:13:52 +00:00
ab312235ba Merge pull request #14 from madaidan/patch-10
Add some hardening for other distributions
2019-06-28 06:59:16 +00:00
5e02100e34 Merge pull request #13 from madaidan/patch-9
Remove System.map and restrict the SysRq key.
2019-06-28 06:58:32 +00:00
7e12e16dc0 Merge pull request #11 from madaidan/patch-7
Protect against DMA attacks
2019-06-28 06:57:42 +00:00
3801a53a9e Update tcp_hardening.conf 2019-06-27 18:17:58 +00:00
c54125270b Create dmesg_restrict.conf 2019-06-27 18:15:57 +00:00
01c839c815 Restrict what the SysRq key can do 2019-06-25 19:16:43 +00:00
2a6289980e syntax fix
GRUB_CMDLINE_LINUX="$GRUB_CMDLINE_LINUX mds=full,nosmt"

https://forums.whonix.org/t/kernel-hardening/7296/70
2019-06-23 18:46:52 +00:00
aec6da28e9 Merge pull request #10 from madaidan/patch-6
Enable more kernel hardening parameters
2019-06-23 18:45:24 +00:00
641407c8e9 Enable IOMMU 2019-06-23 18:38:50 +00:00
07c6362f1a Blacklist thunderbolt and firewire 2019-06-23 18:34:45 +00:00
2178fb37a8 Add more kernel hardening parameters 2019-06-23 17:54:34 +00:00
807ac7d659 Create tcp_sack.conf 2019-06-22 16:08:30 +00:00
49873e8e02 solve package file conflict
https://github.com/QubesOS/qubes-issues/issues/1885#issuecomment-500200375
2019-06-09 10:06:58 +00:00
7177c6041a Create uncommon-network-protocols.conf 2019-05-16 20:30:49 +00:00
7d7b899dd1 Merge pull request #6 from madaidan/patch-2
Even more kernel hardening
2019-05-16 19:52:52 +00:00
b814f338b8 Update tcp_hardening.conf 2019-05-16 16:33:03 +00:00
e6794721bd Update ptrace_scope.conf 2019-05-16 16:29:20 +00:00
137bc073c5 port to /etc/xdg/xfce4/xfconf/xfce-perchannel-xml
https://forums.whonix.org/t/whonix-xfce-development/6213/84?u=patrick
2019-05-08 21:38:25 -04:00
b00a264ce2 Disable thunar-volman by default. 2019-05-08 21:29:36 -04:00
a4852ad6c8 Create fs_protected.conf 2019-05-06 20:37:53 +00:00
0296e51e06 Create ptrace_scope.conf 2019-05-06 15:46:37 +00:00
2923fc96ef Create tcp_hardening.conf 2019-05-06 15:45:53 +00:00
4216299ee8 Create kexec.conf 2019-05-06 15:42:55 +00:00
f917c27a19 remove trailing spaces 2019-05-06 05:51:14 -04:00
02e8888b0b Update 40_kernel_hardening.cfg 2019-05-05 20:17:33 +00:00
3695d7491e Create 40_kernel_hardening.cfg 2019-05-05 14:42:03 +00:00
d2ca85c686 Create mmap_aslr.conf 2019-05-05 14:36:30 +00:00
197c1120a9 Create harden_bpf.conf 2019-05-05 14:35:42 +00:00
351db0ef7f Create kptr_restrict.conf 2019-05-05 14:34:41 +00:00
63b080f40b fix hiding network bookmark in thunar by default
Thanks to @Algernon for suggesting the fix!
2018-11-19 06:27:52 -05:00
daf7fc002b Disables network bookmark by default. 2018-11-19 03:08:20 -05:00
f84f988118 Enabled hidden files and volume management. 2018-11-08 07:22:35 +00:00
5aebf29214 Security and general settings for Thunar. 2018-11-02 10:16:09 +00:00
008a97d9e7 disable previews in thunar 2018-10-31 02:22:43 -04:00
5b3fc2f6b9 update copyright 2018-01-29 15:22:05 +00:00