mirror of
https://github.com/Kicksecure/security-misc.git
synced 2025-03-12 21:56:33 -04:00
Don't worry about files under /bin anymore, Bookworm uses a merged /usr directory
This commit is contained in:
parent
c6be621968
commit
5941195e96
@ -11,4 +11,3 @@
|
||||
#
|
||||
# See also: https://www.kicksecure.com/wiki/SUID_Disabler_and_Permission_Hardener#passwd
|
||||
/usr/bin/passwd 0755 root root
|
||||
/bin/passwd 0755 root root
|
||||
|
@ -17,4 +17,3 @@
|
||||
## compromised network-facing daemon (such as web servers, time synchronization daemons,
|
||||
## etc.) running as its own user from exploiting sudo to escalate privileges.
|
||||
#/usr/bin/sudo 4750 root sudo
|
||||
#/bin/sudo 4750 root sudo
|
||||
|
@ -6,4 +6,3 @@
|
||||
## configuration. When security-misc is updated, this file may be overwritten.
|
||||
|
||||
/usr/bin/bwrap exactwhitelist
|
||||
/bin/bwrap exactwhitelist
|
||||
|
@ -8,14 +8,10 @@
|
||||
## https://forums.whonix.org/t/disable-suid-binaries/7706/61
|
||||
## Protect from 'chmod -x' (and SUID removal).
|
||||
## SUID will be removed below in separate step.
|
||||
/bin/mount exactwhitelist
|
||||
/usr/bin/mount exactwhitelist
|
||||
/bin/umount exactwhitelist
|
||||
/usr/bin/umount exactwhitelist
|
||||
|
||||
## Remove SUID from 'mount' but keep executable.
|
||||
## https://forums.whonix.org/t/disable-suid-binaries/7706/61
|
||||
/bin/mount 755 root root
|
||||
/usr/bin/mount 755 root root
|
||||
/bin/umount 755 root root
|
||||
/usr/bin/umount 755 root root
|
||||
|
@ -6,9 +6,7 @@
|
||||
## configuration. When security-misc is updated, this file may be overwritten.
|
||||
|
||||
/usr/bin/pkexec exactwhitelist
|
||||
/bin/pkexec exactwhitelist
|
||||
/usr/bin/pkexec.security-misc-orig exactwhitelist
|
||||
/bin/pkexec.security-misc-orig exactwhitelist
|
||||
|
||||
## TODO: research
|
||||
## match both:
|
||||
|
@ -6,4 +6,3 @@
|
||||
## configuration. When security-misc is updated, this file may be overwritten.
|
||||
|
||||
/usr/bin/sudo exactwhitelist
|
||||
/bin/sudo exactwhitelist
|
||||
|
Loading…
x
Reference in New Issue
Block a user