mirror of
https://github.com/Kicksecure/security-misc.git
synced 2025-07-25 21:55:20 -04:00
Merge remote-tracking branch 'ArrayBolt3/arraybolt3/usrmerge'
This commit is contained in:
commit
3a31cc99b3
6 changed files with 0 additions and 10 deletions
|
@ -17,4 +17,3 @@
|
||||||
## compromised network-facing daemon (such as web servers, time synchronization daemons,
|
## compromised network-facing daemon (such as web servers, time synchronization daemons,
|
||||||
## etc.) running as its own user from exploiting sudo to escalate privileges.
|
## etc.) running as its own user from exploiting sudo to escalate privileges.
|
||||||
#/usr/bin/sudo 4750 root sudo
|
#/usr/bin/sudo 4750 root sudo
|
||||||
#/bin/sudo 4750 root sudo
|
|
||||||
|
|
|
@ -6,4 +6,3 @@
|
||||||
## configuration. When security-misc is updated, this file may be overwritten.
|
## configuration. When security-misc is updated, this file may be overwritten.
|
||||||
|
|
||||||
/usr/bin/bwrap exactwhitelist
|
/usr/bin/bwrap exactwhitelist
|
||||||
/bin/bwrap exactwhitelist
|
|
||||||
|
|
|
@ -8,14 +8,10 @@
|
||||||
## https://forums.whonix.org/t/disable-suid-binaries/7706/61
|
## https://forums.whonix.org/t/disable-suid-binaries/7706/61
|
||||||
## Protect from 'chmod -x' (and SUID removal).
|
## Protect from 'chmod -x' (and SUID removal).
|
||||||
## SUID will be removed below in separate step.
|
## SUID will be removed below in separate step.
|
||||||
/bin/mount exactwhitelist
|
|
||||||
/usr/bin/mount exactwhitelist
|
/usr/bin/mount exactwhitelist
|
||||||
/bin/umount exactwhitelist
|
|
||||||
/usr/bin/umount exactwhitelist
|
/usr/bin/umount exactwhitelist
|
||||||
|
|
||||||
## Remove SUID from 'mount' but keep executable.
|
## Remove SUID from 'mount' but keep executable.
|
||||||
## https://forums.whonix.org/t/disable-suid-binaries/7706/61
|
## https://forums.whonix.org/t/disable-suid-binaries/7706/61
|
||||||
/bin/mount 755 root root
|
|
||||||
/usr/bin/mount 755 root root
|
/usr/bin/mount 755 root root
|
||||||
/bin/umount 755 root root
|
|
||||||
/usr/bin/umount 755 root root
|
/usr/bin/umount 755 root root
|
||||||
|
|
|
@ -14,4 +14,3 @@
|
||||||
/usr/bin/passwd exactwhitelist
|
/usr/bin/passwd exactwhitelist
|
||||||
/bin/passwd exactwhitelist
|
/bin/passwd exactwhitelist
|
||||||
/usr/bin/passwd 0755 root root
|
/usr/bin/passwd 0755 root root
|
||||||
/bin/passwd 0755 root root
|
|
||||||
|
|
|
@ -6,9 +6,7 @@
|
||||||
## configuration. When security-misc is updated, this file may be overwritten.
|
## configuration. When security-misc is updated, this file may be overwritten.
|
||||||
|
|
||||||
/usr/bin/pkexec exactwhitelist
|
/usr/bin/pkexec exactwhitelist
|
||||||
/bin/pkexec exactwhitelist
|
|
||||||
/usr/bin/pkexec.security-misc-orig exactwhitelist
|
/usr/bin/pkexec.security-misc-orig exactwhitelist
|
||||||
/bin/pkexec.security-misc-orig exactwhitelist
|
|
||||||
|
|
||||||
## TODO: research
|
## TODO: research
|
||||||
## match both:
|
## match both:
|
||||||
|
|
|
@ -6,4 +6,3 @@
|
||||||
## configuration. When security-misc is updated, this file may be overwritten.
|
## configuration. When security-misc is updated, this file may be overwritten.
|
||||||
|
|
||||||
/usr/bin/sudo exactwhitelist
|
/usr/bin/sudo exactwhitelist
|
||||||
/bin/sudo exactwhitelist
|
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue