This commit is contained in:
Patrick Schleizer 2025-01-20 06:28:16 -05:00
parent 8ff5f3b221
commit df9d058ed9
No known key found for this signature in database
GPG Key ID: CB8D50BB77BB3C48
4 changed files with 1 additions and 4 deletions

View File

@ -12,5 +12,4 @@
# #
# See also: https://www.kicksecure.com/wiki/SUID_Disabler_and_Permission_Hardener#passwd # See also: https://www.kicksecure.com/wiki/SUID_Disabler_and_Permission_Hardener#passwd
/usr/bin/passwd exactwhitelist /usr/bin/passwd exactwhitelist
/bin/passwd exactwhitelist
/usr/bin/passwd 0755 root root /usr/bin/passwd 0755 root root

View File

@ -12,4 +12,4 @@
## SSH, and is likely rarely used, thus this should be safe to disable. ## SSH, and is likely rarely used, thus this should be safe to disable.
#ssh-agent matchwhitelist #ssh-agent matchwhitelist
#ssh-keysign matchwhitelist #ssh-keysign matchwhitelist
#/lib/openssh matchwhitelist #/usr/lib/openssh matchwhitelist

View File

@ -8,4 +8,3 @@
## required for performing password validation from unprivileged user ## required for performing password validation from unprivileged user
## processes such as KScreenLocker's unlock prompt ## processes such as KScreenLocker's unlock prompt
/usr/sbin/unix_chkpwd exactwhitelist /usr/sbin/unix_chkpwd exactwhitelist
/sbin/unix_chkpwd exactwhitelist

View File

@ -7,7 +7,6 @@
## TODO: research ## TODO: research
/usr/lib/virtualbox/ matchwhitelist /usr/lib/virtualbox/ matchwhitelist
/lib/virtualbox/ matchwhitelist
VirtualBoxVM matchwhitelist VirtualBoxVM matchwhitelist
VBoxSDL matchwhitelist VBoxSDL matchwhitelist
VBoxNetNAT matchwhitelist VBoxNetNAT matchwhitelist