Repository navigation
Protecting /sys and /proc #277
Description
Activity
That's an interesting repository which might have some goodies that have not been suggested here yet. Created,
for it.
That approach is blacklist based. Enumerating badness.
https://github.com/Kicksecure/security-misc/blob/master/usr/libexec/security-misc/hide-hardware-info approach is whitelist based. Hardening permissions for everything except whitelisted.
It also supports conditionals, configuration, is extensible, could be used to address the other related open issues in this repository one day.
I don't see much code issues with
/usr/libexec/security-misc/hide-hardware-info.It's currently easy to opt-in the hide-hardware-info.service systemd unit using
sudo systemctl enable /hide-hardware-info.service.How would opt-in enabling work?
This is what the script is currently doing:
sudo ./usr/libexec/security-misc/hide-hardware-info./usr/libexec/security-misc/hide-hardware-info: INFO: START INFO: whitelist executing: chgrp --quiet --recursive cpuinfo /proc/cpuinfo INFO: whitelist executing: chmod o-rwx /proc/cpuinfo INFO: normal executing : chmod og-rwx /proc/bus INFO: normal executing : chmod og-rwx /proc/scsi INFO: whitelist executing: chgrp --quiet --recursive sysfs /sys INFO: whitelist executing: chmod o-rwx /sys INFO: normal executing : chmod o-rwx /sys/block INFO: normal executing : chmod o-rwx /sys/bus INFO: normal executing : chmod o-rwx /sys/class INFO: normal executing : chmod o-rwx /sys/dev INFO: normal executing : chmod o-rwx /sys/devices INFO: normal executing : chmod o-rwx /sys/firmware INFO: normal executing : chmod o-rwx /sys/fs INFO: normal executing : chmod o-rwx /sys/hypervisor INFO: normal executing : chmod o-rwx /sys/kernel INFO: normal executing : chmod o-rwx /sys/module INFO: normal executing : chmod o-rwx /sys/power INFO: normal executing : chmod o-rwx /sys/fs/bpf INFO: normal executing : chmod o-rwx /sys/fs/btrfs INFO: normal executing : chmod o-rwx /sys/fs/cgroup INFO: normal executing : chmod o-rwx /sys/fs/ext4 INFO: normal executing : chmod o-rwx /sys/fs/fuse INFO: normal executing : chmod o-rwx /sys/fs/pstore INFO: normal executing : chmod o+rx /sys /sys/fs ./usr/libexec/security-misc/hide-hardware-info: INFO: ENDNot a high priority for me to translate that to systemd-tmpfiles.
We know have our own services to change permissions. I have come across a better and more clean implementation.
https://github.com/divestedcg/Brace/tree/master/brace/usr/lib/tmpfiles.d
Can this approach be used here too for our purposes?