Merge remote-tracking branch 'ArrayBolt3/arraybolt3/usrmerge'

This commit is contained in:
Patrick Schleizer 2025-01-09 09:30:58 -05:00
commit 3a31cc99b3
No known key found for this signature in database
GPG Key ID: CB8D50BB77BB3C48
6 changed files with 0 additions and 10 deletions

View File

@ -17,4 +17,3 @@
## compromised network-facing daemon (such as web servers, time synchronization daemons, ## compromised network-facing daemon (such as web servers, time synchronization daemons,
## etc.) running as its own user from exploiting sudo to escalate privileges. ## etc.) running as its own user from exploiting sudo to escalate privileges.
#/usr/bin/sudo 4750 root sudo #/usr/bin/sudo 4750 root sudo
#/bin/sudo 4750 root sudo

View File

@ -6,4 +6,3 @@
## configuration. When security-misc is updated, this file may be overwritten. ## configuration. When security-misc is updated, this file may be overwritten.
/usr/bin/bwrap exactwhitelist /usr/bin/bwrap exactwhitelist
/bin/bwrap exactwhitelist

View File

@ -8,14 +8,10 @@
## https://forums.whonix.org/t/disable-suid-binaries/7706/61 ## https://forums.whonix.org/t/disable-suid-binaries/7706/61
## Protect from 'chmod -x' (and SUID removal). ## Protect from 'chmod -x' (and SUID removal).
## SUID will be removed below in separate step. ## SUID will be removed below in separate step.
/bin/mount exactwhitelist
/usr/bin/mount exactwhitelist /usr/bin/mount exactwhitelist
/bin/umount exactwhitelist
/usr/bin/umount exactwhitelist /usr/bin/umount exactwhitelist
## Remove SUID from 'mount' but keep executable. ## Remove SUID from 'mount' but keep executable.
## https://forums.whonix.org/t/disable-suid-binaries/7706/61 ## https://forums.whonix.org/t/disable-suid-binaries/7706/61
/bin/mount 755 root root
/usr/bin/mount 755 root root /usr/bin/mount 755 root root
/bin/umount 755 root root
/usr/bin/umount 755 root root /usr/bin/umount 755 root root

View File

@ -14,4 +14,3 @@
/usr/bin/passwd exactwhitelist /usr/bin/passwd exactwhitelist
/bin/passwd exactwhitelist /bin/passwd exactwhitelist
/usr/bin/passwd 0755 root root /usr/bin/passwd 0755 root root
/bin/passwd 0755 root root

View File

@ -6,9 +6,7 @@
## configuration. When security-misc is updated, this file may be overwritten. ## configuration. When security-misc is updated, this file may be overwritten.
/usr/bin/pkexec exactwhitelist /usr/bin/pkexec exactwhitelist
/bin/pkexec exactwhitelist
/usr/bin/pkexec.security-misc-orig exactwhitelist /usr/bin/pkexec.security-misc-orig exactwhitelist
/bin/pkexec.security-misc-orig exactwhitelist
## TODO: research ## TODO: research
## match both: ## match both:

View File

@ -6,4 +6,3 @@
## configuration. When security-misc is updated, this file may be overwritten. ## configuration. When security-misc is updated, this file may be overwritten.
/usr/bin/sudo exactwhitelist /usr/bin/sudo exactwhitelist
/bin/sudo exactwhitelist