From 037022c6d22752644ade585f11b91ca9f3c04abb Mon Sep 17 00:00:00 2001 From: Tommy Date: Sat, 4 Feb 2023 05:21:33 -0500 Subject: [PATCH] Update kicksecure sysctl Signed-off-by: Tommy --- Fedora-Workstation-36.sh | 1 + GCP-Debian-11.sh | 1 + Proxmox-7.sh | 1 + RHEL-Server-9.sh | 3 ++- 4 files changed, 5 insertions(+), 1 deletion(-) diff --git a/Fedora-Workstation-36.sh b/Fedora-Workstation-36.sh index 57f23c4..9856911 100644 --- a/Fedora-Workstation-36.sh +++ b/Fedora-Workstation-36.sh @@ -29,6 +29,7 @@ chmod 700 /home/* curl https://raw.githubusercontent.com/Kicksecure/security-misc/master/etc/modprobe.d/30_security-misc.conf -o /etc/modprobe.d/30_security-misc.conf curl https://raw.githubusercontent.com/Kicksecure/security-misc/master/etc/sysctl.d/30_security-misc.conf -o /etc/sysctl.d/30_security-misc.conf curl https://raw.githubusercontent.com/Kicksecure/security-misc/master/etc/sysctl.d/30_silent-kernel-printk.conf -o /etc/sysctl.d/30_silent-kernel-printk.conf +curl https://raw.githubusercontent.com/Kicksecure/security-misc/master/etc/sysctl.d/30_security-misc_kexec-disable.conf -o /etc/sysctl.d/30_security-misc_kexec-disable.conf #Systemd Hardening mkdir -p /etc/systemd/system/NetworkManager.service.d diff --git a/GCP-Debian-11.sh b/GCP-Debian-11.sh index 378568b..bd5e639 100644 --- a/GCP-Debian-11.sh +++ b/GCP-Debian-11.sh @@ -96,6 +96,7 @@ sudo curl https://raw.githubusercontent.com/Kicksecure/security-misc/master/etc/ sudo curl https://raw.githubusercontent.com/Kicksecure/security-misc/master/etc/sysctl.d/30_security-misc.conf -o /etc/sysctl.d/30_security-misc.conf sudo sed -i 's/kernel.yama.ptrace_scope=2/kernel.yama.ptrace_scope=3/g' /etc/sysctl.d/30_security-misc.conf sudo curl https://raw.githubusercontent.com/Kicksecure/security-misc/master/etc/sysctl.d/30_silent-kernel-printk.conf -o /etc/sysctl.d/30_silent-kernel-printk.conf +sudo curl https://raw.githubusercontent.com/Kicksecure/security-misc/master/etc/sysctl.d/30_security-misc_kexec-disable.conf -o /etc/sysctl.d/30_security-misc_kexec-disable.conf sudo mkdir -p /etc/systemd/system/NetworkManager.service.d sudo curl https://gitlab.com/divested/brace/-/raw/master/brace/usr/lib/systemd/system/NetworkManager.service.d/99-brace.conf -o /etc/systemd/system/NetworkManager.service.d/99-brace.conf diff --git a/Proxmox-7.sh b/Proxmox-7.sh index 8f1ed33..deed553 100644 --- a/Proxmox-7.sh +++ b/Proxmox-7.sh @@ -37,6 +37,7 @@ curl https://raw.githubusercontent.com/Kicksecure/security-misc/master/etc/modpr curl https://raw.githubusercontent.com/Kicksecure/security-misc/master/etc/sysctl.d/30_security-misc.conf -o /etc/sysctl.d/30_security-misc.conf sed -i 's/kernel.yama.ptrace_scope=2/kernel.yama.ptrace_scope=3/g' /etc/sysctl.d/30_security-misc.conf curl https://raw.githubusercontent.com/Kicksecure/security-misc/master/etc/sysctl.d/30_silent-kernel-printk.conf -o /etc/sysctl.d/30_silent-kernel-printk.conf +curl https://raw.githubusercontent.com/Kicksecure/security-misc/master/etc/sysctl.d/30_security-misc_kexec-disable.conf -o /etc/sysctl.d/30_security-misc_kexec-disable.conf mkdir -p /etc/systemd/system/NetworkManager.service.d curl https://gitlab.com/divested/brace/-/raw/master/brace/usr/lib/systemd/system/NetworkManager.service.d/99-brace.conf -o /etc/systemd/system/NetworkManager.service.d/99-brace.conf diff --git a/RHEL-Server-9.sh b/RHEL-Server-9.sh index 2ac088d..bda7c22 100644 --- a/RHEL-Server-9.sh +++ b/RHEL-Server-9.sh @@ -50,7 +50,7 @@ forward-zone: forward-addr: 8.8.4.4#dns.google forward-addr: 2001:4860:4860::8888#dns.google forward-addr: 2001:4860:4860::8844#dns.google' | sudo tee /etc/unbound/unbound.conf - + mkdir -p /etc/systemd/system/unbound.service.d echo $'[Service] MemoryDenyWriteExecute=true @@ -87,6 +87,7 @@ sudo curl https://raw.githubusercontent.com/Kicksecure/security-misc/master/etc/ sudo curl https://raw.githubusercontent.com/Kicksecure/security-misc/master/etc/sysctl.d/30_security-misc.conf -o /etc/sysctl.d/30_security-misc.conf sudo sed -i 's/kernel.yama.ptrace_scope=2/kernel.yama.ptrace_scope=3/g' /etc/sysctl.d/30_security-misc.conf sudo curl https://raw.githubusercontent.com/Kicksecure/security-misc/master/etc/sysctl.d/30_silent-kernel-printk.conf -o /etc/sysctl.d/30_silent-kernel-printk.conf +sudo curl https://raw.githubusercontent.com/Kicksecure/security-misc/master/etc/sysctl.d/30_security-misc_kexec-disable.conf -o /etc/sysctl.d/30_security-misc_kexec-disable.conf sudo sysctl -p sudo mkdir -p /etc/systemd/system/NetworkManager.service.d