Don't worry about files under /bin anymore, Bookworm uses a merged /usr directory

This commit is contained in:
Aaron Rainbolt 2025-01-07 14:10:46 -06:00
parent c6be621968
commit 5941195e96
No known key found for this signature in database
GPG Key ID: A709160D73C79109
6 changed files with 0 additions and 10 deletions

View File

@ -11,4 +11,3 @@
#
# See also: https://www.kicksecure.com/wiki/SUID_Disabler_and_Permission_Hardener#passwd
/usr/bin/passwd 0755 root root
/bin/passwd 0755 root root

View File

@ -17,4 +17,3 @@
## compromised network-facing daemon (such as web servers, time synchronization daemons,
## etc.) running as its own user from exploiting sudo to escalate privileges.
#/usr/bin/sudo 4750 root sudo
#/bin/sudo 4750 root sudo

View File

@ -6,4 +6,3 @@
## configuration. When security-misc is updated, this file may be overwritten.
/usr/bin/bwrap exactwhitelist
/bin/bwrap exactwhitelist

View File

@ -8,14 +8,10 @@
## https://forums.whonix.org/t/disable-suid-binaries/7706/61
## Protect from 'chmod -x' (and SUID removal).
## SUID will be removed below in separate step.
/bin/mount exactwhitelist
/usr/bin/mount exactwhitelist
/bin/umount exactwhitelist
/usr/bin/umount exactwhitelist
## Remove SUID from 'mount' but keep executable.
## https://forums.whonix.org/t/disable-suid-binaries/7706/61
/bin/mount 755 root root
/usr/bin/mount 755 root root
/bin/umount 755 root root
/usr/bin/umount 755 root root

View File

@ -6,9 +6,7 @@
## configuration. When security-misc is updated, this file may be overwritten.
/usr/bin/pkexec exactwhitelist
/bin/pkexec exactwhitelist
/usr/bin/pkexec.security-misc-orig exactwhitelist
/bin/pkexec.security-misc-orig exactwhitelist
## TODO: research
## match both:

View File

@ -6,4 +6,3 @@
## configuration. When security-misc is updated, this file may be overwritten.
/usr/bin/sudo exactwhitelist
/bin/sudo exactwhitelist