From a0db80db160c032a2762c4be040b0aced5cb996a Mon Sep 17 00:00:00 2001 From: Alexander Popov Date: Thu, 28 Nov 2019 19:28:52 +0300 Subject: [PATCH] Save more hardening sysctls for TODO --- kconfig-hardened-check.py | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/kconfig-hardened-check.py b/kconfig-hardened-check.py index 97cb913..5c60fb7 100755 --- a/kconfig-hardened-check.py +++ b/kconfig-hardened-check.py @@ -36,8 +36,13 @@ # kptr_restrict=2 # vm.unprivileged_userfaultfd=0 # kernel.perf_event_paranoid=3 -# kernel.yama.ptrace_scope=1 +# kernel.yama.ptrace_scope=1 (or even 3?) # kernel.unprivileged_bpf_disabled=1 +# fs.suid_dumpable=0 +# fs.protected_symlinks = 1 +# fs.protected_hardlinks = 1 +# fs.protected_fifos = 2 +# fs.protected_regular = 2 import sys from argparse import ArgumentParser -- 2.31.1