Patrick Schleizer
|
f3ff32ddbb
|
Protect /bin/mount from 'chmod -x'.
/bin/mount exactwhitelist
/usr/bin/mount exactwhitelist
Remove SUID from 'mount' but keep executable.
/bin/mount 745 root root
/usr/bin/mount 745 root root
https://forums.whonix.org/t/disable-suid-binaries/7706/61
|
2019-12-30 06:39:24 -05:00 |
|
Patrick Schleizer
|
e4e9c4e3b0
|
bumped changelog version
|
2019-12-30 05:59:43 -05:00 |
|
Patrick Schleizer
|
9c0d6b6057
|
copyright
|
2019-12-29 05:09:07 -05:00 |
|
Patrick Schleizer
|
edc08988f2
|
copyright
|
2019-12-29 05:08:53 -05:00 |
|
Patrick Schleizer
|
9156d3584c
|
Description
|
2019-12-29 04:59:05 -05:00 |
|
Patrick Schleizer
|
3ea946b365
|
RemainAfterExit=yes
|
2019-12-29 04:56:51 -05:00 |
|
Patrick Schleizer
|
2787ae9765
|
copyright
|
2019-12-29 04:56:35 -05:00 |
|
Patrick Schleizer
|
6d56eb9ef0
|
minor
|
2019-12-29 04:56:18 -05:00 |
|
Patrick Schleizer
|
0e14706f32
|
copyright
|
2019-12-29 04:45:26 -05:00 |
|
Patrick Schleizer
|
1a0f7a7733
|
debugging
|
2019-12-29 04:43:32 -05:00 |
|
Patrick Schleizer
|
5271892cb1
|
debugging
|
2019-12-29 04:42:54 -05:00 |
|
Patrick Schleizer
|
683028049c
|
debugging
|
2019-12-29 04:41:23 -05:00 |
|
Patrick Schleizer
|
e3e1ff2a31
|
exit with error if a config line cannot be processed rather than skipping
https://forums.whonix.org/t/disable-suid-binaries/7706/59
|
2019-12-29 04:35:46 -05:00 |
|
Patrick Schleizer
|
d5c99f3a60
|
output
|
2019-12-29 04:27:21 -05:00 |
|
Patrick Schleizer
|
e5623fcd2b
|
comment
|
2019-12-29 04:21:52 -05:00 |
|
Patrick Schleizer
|
d7f58db52c
|
bumped changelog version
|
2019-12-27 05:30:12 -05:00 |
|
Patrick Schleizer
|
674840e6f9
|
/fusermount matchwhitelist
unbreak AppImages such as electrum Bitcoin wallet
https://forums.whonix.org/t/disable-suid-binaries/7706/57
|
2019-12-26 05:44:35 -05:00 |
|
Patrick Schleizer
|
507a30d6e3
|
bumped changelog version
|
2019-12-24 18:35:49 -05:00 |
|
Patrick Schleizer
|
04f438f75d
|
comment
|
2019-12-24 18:09:37 -05:00 |
|
Patrick Schleizer
|
9da0e428ed
|
debugging
|
2019-12-24 17:54:31 -05:00 |
|
Patrick Schleizer
|
e18ec533c3
|
comment
|
2019-12-24 17:54:02 -05:00 |
|
Patrick Schleizer
|
0326cd5ee9
|
bumped changelog version
|
2019-12-24 08:07:55 -05:00 |
|
Patrick Schleizer
|
ede536913d
|
no longer hardcode amd64
|
2019-12-24 06:00:41 -05:00 |
|
Patrick Schleizer
|
d03a3d9ac0
|
Merge remote-tracking branch 'origin/master'
|
2019-12-24 05:57:24 -05:00 |
|
Patrick Schleizer
|
27a42a9da8
|
Merge pull request #50 from madaidan/modules
Make /lib/modules unreadable
|
2019-12-24 10:55:11 +00:00 |
|
Patrick Schleizer
|
ac49c55d1f
|
Merge pull request #49 from madaidan/kver
Detect kernel upgrades
|
2019-12-24 10:55:03 +00:00 |
|
Patrick Schleizer
|
0c3d4ad255
|
Merge pull request #48 from madaidan/kernel-hardening
Use only one slub_debug parameter
|
2019-12-24 10:54:23 +00:00 |
|
madaidan
|
79241c5d09
|
Make /lib/modules unreadable
|
2019-12-23 20:28:29 +00:00 |
|
madaidan
|
98e88d1456
|
Detect kernel upgrades
|
2019-12-23 19:57:43 +00:00 |
|
madaidan
|
d1a0650fd9
|
Use only one slub_debug parameter
|
2019-12-23 19:44:52 +00:00 |
|
Patrick Schleizer
|
9d77d88a4d
|
comments
|
2019-12-23 09:39:50 -05:00 |
|
Patrick Schleizer
|
7a80837b4f
|
bumped changelog version
|
2019-12-23 08:48:04 -05:00 |
|
Patrick Schleizer
|
617c0a0e15
|
disable remount-secure.service - Disable for now until development finished / tested.
|
2019-12-23 07:21:26 -05:00 |
|
Patrick Schleizer
|
3e131174d5
|
comments
|
2019-12-23 05:00:35 -05:00 |
|
Patrick Schleizer
|
bef41a38c2
|
bumped changelog version
|
2019-12-23 03:58:00 -05:00 |
|
Patrick Schleizer
|
046ceeae4d
|
readme
|
2019-12-23 03:57:36 -05:00 |
|
Patrick Schleizer
|
9f072ce4f9
|
comment
|
2019-12-23 03:46:02 -05:00 |
|
Patrick Schleizer
|
26fe9394ff
|
disable lockdown for now due to module loading
|
2019-12-23 03:41:54 -05:00 |
|
Patrick Schleizer
|
9ec5b0ee82
|
description: lockdown not enabled yet
|
2019-12-23 03:38:49 -05:00 |
|
Patrick Schleizer
|
b05669accf
|
Merge branch 'madaidan-kernel-hardening'
|
2019-12-23 03:38:04 -05:00 |
|
Patrick Schleizer
|
1ff51ee061
|
merge
|
2019-12-23 03:37:28 -05:00 |
|
madaidan
|
535c258b83
|
More kernel hardening
|
2019-12-23 03:35:07 -05:00 |
|
Patrick Schleizer
|
11b4192fbd
|
comments
|
2019-12-23 03:28:42 -05:00 |
|
Patrick Schleizer
|
42ff53e9ad
|
bumped changelog version
|
2019-12-23 02:42:07 -05:00 |
|
Patrick Schleizer
|
2152fa2d61
|
comment
|
2019-12-23 02:38:53 -05:00 |
|
Patrick Schleizer
|
f8f2e6c704
|
fix disablewhitelist feature
|
2019-12-23 02:35:13 -05:00 |
|
Patrick Schleizer
|
47ddcad0c0
|
rename keyword whitelist to exactwhitelist
add new keyword disablewhitelist
refactoring
|
2019-12-23 02:29:47 -05:00 |
|
Patrick Schleizer
|
175d1c2845
|
bumped changelog version
|
2019-12-23 02:13:13 -05:00 |
|
Patrick Schleizer
|
0409aac3ae
|
readme
|
2019-12-23 02:09:04 -05:00 |
|
Patrick Schleizer
|
1ff56625a1
|
polkit-agent-helper-1 matchwhitelist to match both
- /usr/lib/policykit-1/polkit-agent-helper-1 matchwhitelist
- /lib/policykit-1/polkit-agent-helper-1
|
2019-12-23 01:42:03 -05:00 |
|