Commit Graph

1464 Commits

Author SHA1 Message Date
6033de7815 debugging 2022-11-15 11:58:50 -05:00
2319458e9f bumped changelog version 25.9-1 2022-08-24 18:28:39 -04:00
cdfc175953 Merge remote-tracking branch 'github-kicksecure/master' 2022-08-22 06:09:30 -04:00
ae4d4989b0 Merge pull request #113 from raja-grewal/master
Comment out machine check exception
2022-08-22 06:09:40 -04:00
d500205f55 Update README.md 2022-08-21 23:03:13 +10:00
92669dba18 Comment out machine check exception 2022-08-21 23:02:44 +10:00
ff8451469a bumped changelog version 25.8-1 2022-08-13 11:40:04 -04:00
272a33fe2c addgroup -> adduser fix 2022-08-13 11:35:25 -04:00
7d5246693c bumped changelog version 25.7-1 2022-08-12 07:52:26 -04:00
82da4ed18f comments 2022-07-28 09:56:24 -04:00
a6bee1493d cold-boot-attack-defense wait longer to make messages readable by user 2022-07-28 09:55:12 -04:00
1095949523 bumped changelog version 25.6-1 2022-07-26 10:00:53 -04:00
053142cdb5 fix 2022-07-26 10:00:21 -04:00
73f6523e09 bumped changelog version 25.5-1 2022-07-23 08:07:37 -04:00
0c5b1e9f57 undo "force kernel to panic on "oopses"
because implemented differently already

https://forums.whonix.org/t/set-oops-panic-kernel-parameter-or-kernel-panic-on-oops-1-sysctl-for-better-security/7713
2022-07-23 07:49:56 -04:00
c1c04b4619 Merge remote-tracking branch 'github-kicksecure/master' 2022-07-23 07:43:19 -04:00
bfe6b88839 Merge pull request #111 from raja-grewal/harden
Increased kernel hardening at boot
2022-07-23 07:27:24 -04:00
ca764d8de0 force kernel to panic on "oopses" 2022-07-20 04:06:35 +10:00
1660aaa6dd update details around disabling SMT 2022-07-19 03:38:41 +10:00
bfd78a2c06 update SRBDS mitigation 2022-07-19 03:16:08 +10:00
c3ebb9160f CPU mitigation - MMIO Stale Data 2022-07-19 02:33:16 +10:00
59e90ff122 CPU mitigation - L1D FLushing 2022-07-19 02:32:41 +10:00
8531fbf99d CPU mitigation - SRBDS 2022-07-19 02:30:49 +10:00
73f1e23332 shuffle and rewording 2022-07-19 02:29:46 +10:00
39314b2912 Merge branch 'harden' of https://github.com/raja-grewal/security-misc into harden 2022-07-19 00:49:08 +10:00
bb831d57bc delete repeated commands 2022-07-19 00:38:32 +10:00
c77a2a78bc enforce default net.ipv6.icmp_ignore_bogus_error_responses 2022-07-19 00:37:31 +10:00
c4a1094760 Merge branch 'Kicksecure:master' into harden 2022-07-18 13:36:23 +00:00
465775c9dc bumped changelog version 25.4-1 2022-07-16 08:00:16 -04:00
1fafb5f53b Merge remote-tracking branch 'github-kicksecure/master' 2022-07-15 08:09:16 -04:00
27aa5231e2 Merge pull request #112 from raja-grewal/blacklist
Corrected kernel module disabling
2022-07-15 08:06:08 -04:00
a72bbb1883 Corrected kerenl module disabling 2022-07-13 23:42:13 +10:00
24d6a93eac bumped changelog version 25.3-1 2022-07-13 08:28:34 -04:00
2b237039cf Update README.md 2022-07-13 22:25:53 +10:00
8f31e5d1d1 Merge remote-tracking branch 'github-kicksecure/master' 2022-07-13 07:26:58 -04:00
c410890a8a Merge pull request #110 from raja-grewal/master
Incorporated Ubuntu’s kernel module blacklists and more verbose errors
2022-07-13 07:24:12 -04:00
4e93b4d37e Revert "enforce defualt net.ipv4.ip_forward"
This reverts commit 57b5b2145c.
2022-07-13 21:10:39 +10:00
a47922ad28 enforce of IOMMU TLB invalidation 2022-07-13 04:47:07 +10:00
33df16af80 disables random.trust_bootloader 2022-07-13 04:37:03 +10:00
d0779a96fc add reference 2022-07-13 04:36:34 +10:00
74858d257b enable randomize_kstack_offset 2022-07-13 04:34:35 +10:00
f572332108 disable slub_debug 2022-07-13 04:32:03 +10:00
57b5b2145c enforce defualt net.ipv4.ip_forward 2022-07-13 04:30:43 +10:00
79156262c9 enforce default net.ipv4.icmp_ignore_bogus_error_responses 2022-07-13 04:29:42 +10:00
dabcaf22e1 enforce default kernel.randomize_va_space 2022-07-13 04:28:03 +10:00
fe0cc10890 Updated README.md 2022-07-12 17:18:47 +10:00
48089e5ba4 More verbose kernel module blocking error logs 2022-07-12 17:02:12 +10:00
40ec791774 Updated comments 2022-07-12 16:58:16 +10:00
ef1ef9917d Blacklist automatic loading of CD-ROM modules 2022-07-10 04:53:25 +10:00
61ef9bd59f Incorporated Ubuntu’s kernel module blacklists 2022-07-10 04:52:00 +10:00