From: Alexander Popov Date: Thu, 28 Nov 2019 16:28:52 +0000 (+0300) Subject: Save more hardening sysctls for TODO X-Git-Tag: v0.5.3~13 X-Git-Url: https://jxself.org/git/?a=commitdiff_plain;h=a0db80db160c032a2762c4be040b0aced5cb996a;p=kconfig-hardened-check.git Save more hardening sysctls for TODO --- diff --git a/kconfig-hardened-check.py b/kconfig-hardened-check.py index 97cb913..5c60fb7 100755 --- a/kconfig-hardened-check.py +++ b/kconfig-hardened-check.py @@ -36,8 +36,13 @@ # kptr_restrict=2 # vm.unprivileged_userfaultfd=0 # kernel.perf_event_paranoid=3 -# kernel.yama.ptrace_scope=1 +# kernel.yama.ptrace_scope=1 (or even 3?) # kernel.unprivileged_bpf_disabled=1 +# fs.suid_dumpable=0 +# fs.protected_symlinks = 1 +# fs.protected_hardlinks = 1 +# fs.protected_fifos = 2 +# fs.protected_regular = 2 import sys from argparse import ArgumentParser