Skip to content

Protecting /sys and /proc #277

Description

We know have our own services to change permissions. I have come across a better and more clean implementation.

https://github.com/divestedcg/Brace/tree/master/brace/usr/lib/tmpfiles.d

Can this approach be used here too for our purposes?

Activity

  1. adrelanos commented on Oct 20, 2024

    @adrelanos
    Contributor

    That's an interesting repository which might have some goodies that have not been suggested here yet. Created,

    for it.

    That approach is blacklist based. Enumerating badness.

    https://github.com/Kicksecure/security-misc/blob/master/usr/libexec/security-misc/hide-hardware-info approach is whitelist based. Hardening permissions for everything except whitelisted.

    It also supports conditionals, configuration, is extensible, could be used to address the other related open issues in this repository one day.

  2. adrelanos commented on Oct 28, 2024

    @adrelanos
    Contributor

    I don't see much code issues with /usr/libexec/security-misc/hide-hardware-info.

    It's currently easy to opt-in the hide-hardware-info.service systemd unit using sudo systemctl enable /hide-hardware-info.service.

    How would opt-in enabling work?

    This is what the script is currently doing:

    sudo ./usr/libexec/security-misc/hide-hardware-info
    
    ./usr/libexec/security-misc/hide-hardware-info: INFO: START
    INFO: whitelist executing: chgrp --quiet --recursive cpuinfo /proc/cpuinfo
    INFO: whitelist executing: chmod o-rwx /proc/cpuinfo
    INFO: normal executing   : chmod og-rwx /proc/bus
    INFO: normal executing   : chmod og-rwx /proc/scsi
    INFO: whitelist executing: chgrp --quiet --recursive sysfs /sys
    INFO: whitelist executing: chmod o-rwx /sys
    INFO: normal executing   : chmod o-rwx /sys/block
    INFO: normal executing   : chmod o-rwx /sys/bus
    INFO: normal executing   : chmod o-rwx /sys/class
    INFO: normal executing   : chmod o-rwx /sys/dev
    INFO: normal executing   : chmod o-rwx /sys/devices
    INFO: normal executing   : chmod o-rwx /sys/firmware
    INFO: normal executing   : chmod o-rwx /sys/fs
    INFO: normal executing   : chmod o-rwx /sys/hypervisor
    INFO: normal executing   : chmod o-rwx /sys/kernel
    INFO: normal executing   : chmod o-rwx /sys/module
    INFO: normal executing   : chmod o-rwx /sys/power
    INFO: normal executing   : chmod o-rwx /sys/fs/bpf
    INFO: normal executing   : chmod o-rwx /sys/fs/btrfs
    INFO: normal executing   : chmod o-rwx /sys/fs/cgroup
    INFO: normal executing   : chmod o-rwx /sys/fs/ext4
    INFO: normal executing   : chmod o-rwx /sys/fs/fuse
    INFO: normal executing   : chmod o-rwx /sys/fs/pstore
    INFO: normal executing   : chmod o+rx /sys /sys/fs
    ./usr/libexec/security-misc/hide-hardware-info: INFO: END
    

    Not a high priority for me to translate that to systemd-tmpfiles.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions