Commit Graph

948 Commits

Author SHA1 Message Date
788914de95 group ssh check was removed
https://forums.whonix.org/t/etc-security-hardening-console-lockdown-pam-access-access-conf/8592/27
2019-12-31 02:46:32 -05:00
06ed728d79 bumped changelog version 13.8-1 2019-12-30 06:42:14 -05:00
f3ff32ddbb Protect /bin/mount from 'chmod -x'.
/bin/mount exactwhitelist
/usr/bin/mount exactwhitelist

Remove SUID from 'mount' but keep executable.

/bin/mount 745 root root
/usr/bin/mount 745 root root

https://forums.whonix.org/t/disable-suid-binaries/7706/61
2019-12-30 06:39:24 -05:00
e4e9c4e3b0 bumped changelog version 13.7-1 2019-12-30 05:59:43 -05:00
9c0d6b6057 copyright 2019-12-29 05:09:07 -05:00
edc08988f2 copyright 2019-12-29 05:08:53 -05:00
9156d3584c Description 2019-12-29 04:59:05 -05:00
3ea946b365 RemainAfterExit=yes 2019-12-29 04:56:51 -05:00
2787ae9765 copyright 2019-12-29 04:56:35 -05:00
6d56eb9ef0 minor 2019-12-29 04:56:18 -05:00
0e14706f32 copyright 2019-12-29 04:45:26 -05:00
1a0f7a7733 debugging 2019-12-29 04:43:32 -05:00
5271892cb1 debugging 2019-12-29 04:42:54 -05:00
683028049c debugging 2019-12-29 04:41:23 -05:00
e3e1ff2a31 exit with error if a config line cannot be processed rather than skipping
https://forums.whonix.org/t/disable-suid-binaries/7706/59
2019-12-29 04:35:46 -05:00
d5c99f3a60 output 2019-12-29 04:27:21 -05:00
e5623fcd2b comment 2019-12-29 04:21:52 -05:00
d7f58db52c bumped changelog version 13.6-1 2019-12-27 05:30:12 -05:00
674840e6f9 /fusermount matchwhitelist
unbreak AppImages such as electrum Bitcoin wallet

https://forums.whonix.org/t/disable-suid-binaries/7706/57
2019-12-26 05:44:35 -05:00
507a30d6e3 bumped changelog version 13.5-1 2019-12-24 18:35:49 -05:00
04f438f75d comment 2019-12-24 18:09:37 -05:00
9da0e428ed debugging 2019-12-24 17:54:31 -05:00
e18ec533c3 comment 2019-12-24 17:54:02 -05:00
0326cd5ee9 bumped changelog version 13.4-1 2019-12-24 08:07:55 -05:00
ede536913d no longer hardcode amd64 2019-12-24 06:00:41 -05:00
d03a3d9ac0 Merge remote-tracking branch 'origin/master' 2019-12-24 05:57:24 -05:00
27a42a9da8 Merge pull request #50 from madaidan/modules
Make /lib/modules unreadable
2019-12-24 10:55:11 +00:00
ac49c55d1f Merge pull request #49 from madaidan/kver
Detect kernel upgrades
2019-12-24 10:55:03 +00:00
0c3d4ad255 Merge pull request #48 from madaidan/kernel-hardening
Use only one slub_debug parameter
2019-12-24 10:54:23 +00:00
79241c5d09 Make /lib/modules unreadable 2019-12-23 20:28:29 +00:00
98e88d1456 Detect kernel upgrades 2019-12-23 19:57:43 +00:00
d1a0650fd9 Use only one slub_debug parameter 2019-12-23 19:44:52 +00:00
9d77d88a4d comments 2019-12-23 09:39:50 -05:00
7a80837b4f bumped changelog version 13.3-1 2019-12-23 08:48:04 -05:00
617c0a0e15 disable remount-secure.service - Disable for now until development finished / tested. 2019-12-23 07:21:26 -05:00
3e131174d5 comments 2019-12-23 05:00:35 -05:00
bef41a38c2 bumped changelog version 13.2-1 2019-12-23 03:58:00 -05:00
046ceeae4d readme 2019-12-23 03:57:36 -05:00
9f072ce4f9 comment 2019-12-23 03:46:02 -05:00
26fe9394ff disable lockdown for now due to module loading 2019-12-23 03:41:54 -05:00
9ec5b0ee82 description: lockdown not enabled yet 2019-12-23 03:38:49 -05:00
b05669accf Merge branch 'madaidan-kernel-hardening' 2019-12-23 03:38:04 -05:00
1ff51ee061 merge 2019-12-23 03:37:28 -05:00
535c258b83 More kernel hardening 2019-12-23 03:35:07 -05:00
11b4192fbd comments 2019-12-23 03:28:42 -05:00
42ff53e9ad bumped changelog version 13.1-1 2019-12-23 02:42:07 -05:00
2152fa2d61 comment 2019-12-23 02:38:53 -05:00
f8f2e6c704 fix disablewhitelist feature 2019-12-23 02:35:13 -05:00
47ddcad0c0 rename keyword whitelist to exactwhitelist
add new keyword disablewhitelist

refactoring
2019-12-23 02:29:47 -05:00
175d1c2845 bumped changelog version 13.0-1 2019-12-23 02:13:13 -05:00