This commit is contained in:
Patrick Schleizer 2019-12-21 07:49:29 -05:00
parent b74e5ca972
commit 161b6f6b88
No known key found for this signature in database
GPG Key ID: CB8D50BB77BB3C48

View File

@ -205,7 +205,7 @@ A systemd service removed SUID / GUID from non-essential binaries as these are
often used in privilege escalation attacks. often used in privilege escalation attacks.
It is disabled by default for now during testing and can optionally be enabled It is disabled by default for now during testing and can optionally be enabled
by running `systemctl enable permission-hardening.service` as root. by running `systemctl enable permission-hardening.service` as root.
https://forums.whonix.org/t/permission-hardening/8655 https://forums.whonix.org/t/disable-suid-binaries/7706
/usr/lib/security-misc/permission-hardening /usr/lib/security-misc/permission-hardening
/lib/systemd/system/permission-hardening.service /lib/systemd/system/permission-hardening.service
/etc/permission-hardening.d/30_default.conf /etc/permission-hardening.d/30_default.conf