mirror of
https://github.com/Kicksecure/security-misc.git
synced 2025-02-17 15:14:11 -05:00
Clarify README.mmd relating to module disabling
This commit is contained in:
parent
98580bb39a
commit
8f2ec75f81
@ -143,7 +143,8 @@ modules from automatically starting.
|
|||||||
Specific kernel modules are entirely disabled to reduce attack surface via
|
Specific kernel modules are entirely disabled to reduce attack surface via
|
||||||
`/etc/modprobe.d/30_security-misc_disable.conf`. Disabling prohibits kernel
|
`/etc/modprobe.d/30_security-misc_disable.conf`. Disabling prohibits kernel
|
||||||
modules from starting. This approach should not be considered comprehensive,
|
modules from starting. This approach should not be considered comprehensive,
|
||||||
rather it is a form of badness enumeration.
|
rather it is a form of badness enumeration. Any potential candidates for future
|
||||||
|
disabling should first be blacklisted for a suitable amount of time.
|
||||||
|
|
||||||
- File Systems: Disable uncommon and legacy file systems.
|
- File Systems: Disable uncommon and legacy file systems.
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user