security-misc/etc
Patrick Schleizer 6479c883bf
Console Lockdown.
Allow members of group 'console' to use tty1 to tty7. Everyone else except
members of group 'console-unrestricted' are restricted from using console
using ancient, unpopular login methods such as using /bin/login over networks,
which might be exploitable. (CVE-2001-0797)

Not enabled by default in this package since this package does not know which
users shall be added to group 'console'.

In new Whonix builds, user 'user" will be added to group 'console' and
pam console-lockdown enabled by package anon-base-files.

/usr/share/pam-configs/console-lockdown

/etc/security/access-security-misc.conf

https://forums.whonix.org/t/etc-security-hardening/8592
2019-12-07 05:40:20 -05:00
..
apparmor.d /dev/pts/[0-9]* rw, 2019-11-26 17:12:12 +00:00
apt/apt.conf.d Enable APT seccomp sandboxing. 2019-07-07 09:37:25 +00:00
default/grub.d description / comments 2019-12-03 02:18:32 -05:00
hide-hardware-info.d copyright 2019-10-31 11:19:44 -04:00
kernel/postinst.d add hook etc/kernel/postinst.d/30_remove-system-map to remove system.map 2019-08-14 07:22:14 +00:00
modprobe.d Elaborate 2019-10-16 18:52:14 +00:00
security Console Lockdown. 2019-12-07 05:40:20 -05:00
skel/.config/xfce4/xfconf/xfce-perchannel-xml solve package file conflict 2019-06-09 10:06:58 +00:00
sudoers.d copyright 2019-10-31 11:19:44 -04:00
sysctl.d comment 2019-12-05 15:52:24 -05:00
systemd/system fix path 2019-07-17 21:02:48 +00:00
thunderbird/pref Enables punycode (network.IDN_show_punycode) by default in Thunderbird 2019-11-03 02:50:51 -05:00
X11/Xsession.d copyright 2019-10-31 11:19:44 -04:00
securetty.security-misc Don't allow root login from a terminal 2019-07-08 23:17:17 +00:00