Update control

This commit is contained in:
madaidan 2019-06-28 11:34:35 +00:00 committed by GitHub
parent b26d861dff
commit 9e9c854d27
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

10
debian/control vendored
View File

@ -97,13 +97,13 @@ Description: enhances misc security settings
.
DCCP, SCTP, TIPC and RDS are blacklisted as they are rarely used and may have
unknown vulnerabilities.
.
The kernel logs are restricted to root only.
.
A systemd service clears System.map on boot as these contain kernel symbols that could be useful to an attacker.
.
The SysRq key is restricted to only allow shutdowns/reboots.
.
The thunderbolt and firewire modules are blacklisted as they can be used for DMA (Direct Memory Access) attacks.
.
IOMMU is enabled with a boot parameter to prevent DMA attacks.