From f1e972f1dec8cb6ef15ef06d0887eb7f0c4735cb Mon Sep 17 00:00:00 2001 From: Alexander Popov Date: Tue, 17 Oct 2023 23:34:14 +0300 Subject: [PATCH] Add kspp-recommendations/kspp-sysctl.txt --- .../kspp-recommendations/kspp-sysctl.txt | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) create mode 100644 kernel_hardening_checker/config_files/kspp-recommendations/kspp-sysctl.txt diff --git a/kernel_hardening_checker/config_files/kspp-recommendations/kspp-sysctl.txt b/kernel_hardening_checker/config_files/kspp-recommendations/kspp-sysctl.txt new file mode 100644 index 0000000..9f99c6c --- /dev/null +++ b/kernel_hardening_checker/config_files/kspp-recommendations/kspp-sysctl.txt @@ -0,0 +1,18 @@ +kernel.printk = 3 4 1 7 +kernel.kptr_restrict = 2 +kernel.dmesg_restrict = 1 +kernel.perf_event_paranoid = 3 +kernel.kexec_load_disabled = 1 +kernel.randomize_va_space = 2 +kernel.yama.ptrace_scope = 3 +user.max_user_namespaces = 0 +dev.tty.ldisc_autoload = 0 +dev.tty.legacy_tiocsti = 0 +kernel.unprivileged_bpf_disabled = 1 +net.core.bpf_jit_harden = 2 +vm.unprivileged_userfaultfd = 0 +fs.protected_symlinks = 1 +fs.protected_hardlinks = 1 +fs.protected_fifos = 2 +fs.protected_regular = 2 +fs.suid_dumpable = 0 -- 2.31.1