Improved network hardening

This commit is contained in:
Tad 2017-06-28 08:20:24 -04:00
parent e343f5b465
commit 82be2c12f5
5 changed files with 177 additions and 85 deletions

View file

@ -154,10 +154,11 @@ patch -p1 < $patches"android_packages_inputmethods_LatinIME/0001-Voice.patch" #R
enter "system/core"
cat /tmp/ar/hosts >> rootdir/etc/hosts #Merge in our HOSTS file
patch -p1 < $patches"android_system_core/0001-Hardening.patch" #Misc hardening
patch -p1 < $patches"android_system_core/0001-Harden_Mounts.patch" #Harden mounts with nodev/noexec/nosuid
patch -p1 < $patches"android_system_core/0002-Harden_Network.patch" #Harden network via sysctls
enter "system/netd"
patch -p1 < $patches"android_system_netd/0001-iptables.patch"; #Network hardening via iptables
patch -p1 < $patches"android_system_netd/0001-Harden_Network.patch"; #Harden network via iptables
enter "vendor/cm"
awk -i inplace '!/50-cm.sh/' config/common.mk; #Make sure our hosts is always used