diff --git a/Fedora-Server-40.sh b/Fedora-Server-40.sh index 695b0ab..5abaf56 100644 --- a/Fedora-Server-40.sh +++ b/Fedora-Server-40.sh @@ -69,7 +69,7 @@ sudo systemctl daemon-reload sudo systemctl restart sshd # Security kernel settings -unpriv curl -s https://raw.githubusercontent.com/secureblue/secureblue/live/files/system/usr/etc/modprobe.d/blacklist.conf | sudo tee /etc/modprobe.d/server-blacklist.conf > /dev/null +unpriv curl -s https://raw.githubusercontent.com/secureblue/secureblue/live/files/system/etc/modprobe.d/blacklist.conf | sudo tee /etc/modprobe.d/server-blacklist.conf > /dev/null sudo chmod 644 /etc/modprobe.d/server-blacklist.conf unpriv curl -s https://raw.githubusercontent.com/TommyTran732/Linux-Setup-Scripts/main/etc/sysctl.d/99-server.conf | sudo tee /etc/sysctl.d/99-server.conf > /dev/null sudo chmod 644 /etc/sysctl.d/99-server.conf diff --git a/Fedora-Workstation-40.sh b/Fedora-Workstation-40.sh index 6778795..46fdcb6 100644 --- a/Fedora-Workstation-40.sh +++ b/Fedora-Workstation-40.sh @@ -67,7 +67,7 @@ sudo chmod 644 /etc/ssh/ssh_config.d/10-custom.conf if [ "${virtualization}" = 'parallels' ]; then unpriv curl -s https://raw.githubusercontent.com/TommyTran732/Kernel-Module-Blacklist/main/etc/modprobe.d/workstation-blacklist.conf | sudo tee /etc/modprobe.d/workstation-blacklist.conf > /dev/null else - unpriv curl -s https://raw.githubusercontent.com/secureblue/secureblue/live/files/system/usr/etc/modprobe.d/blacklist.conf | sudo tee /etc/modprobe.d/workstation-blacklist.conf > /dev/null + unpriv curl -s https://raw.githubusercontent.com/secureblue/secureblue/live/files/system/etc/modprobe.d/blacklist.conf | sudo tee /etc/modprobe.d/workstation-blacklist.conf > /dev/null fi sudo chmod 644 /etc/modprobe.d/workstation-blacklist.conf unpriv curl -s https://raw.githubusercontent.com/TommyTran732/Linux-Setup-Scripts/main/etc/sysctl.d/99-workstation.conf | sudo tee /etc/sysctl.d/99-workstation.conf > /dev/null diff --git a/Proxmox-8.sh b/Proxmox-8.sh index 5e3829c..c6a56e7 100644 --- a/Proxmox-8.sh +++ b/Proxmox-8.sh @@ -74,7 +74,7 @@ proxmox-boot-tool refresh ### # Kernel hardening -curl -s https://raw.githubusercontent.com/secureblue/secureblue/live/files/system/usr/etc/modprobe.d/blacklist.conf | tee /etc/modprobe.d/server-blacklist.conf > /dev/null +curl -s https://raw.githubusercontent.com/secureblue/secureblue/live/files/system/etc/modprobe.d/blacklist.conf | tee /etc/modprobe.d/server-blacklist.conf > /dev/null curl -s https://raw.githubusercontent.com/TommyTran732/Linux-Setup-Scripts/main/etc/sysctl.d/99-server.conf | tee /etc/sysctl.d/99-server.conf > /dev/null sysctl -p diff --git a/RHEL-9.sh b/RHEL-9.sh index a00c350..589c877 100644 --- a/RHEL-9.sh +++ b/RHEL-9.sh @@ -63,7 +63,7 @@ sudo systemctl daemon-reload sudo systemctl restart sshd # Security kernel settings -unpriv curl -s https://raw.githubusercontent.com/secureblue/secureblue/live/files/system/usr/etc/modprobe.d/blacklist.conf | sudo tee /etc/modprobe.d/server-blacklist.conf > /dev/null +unpriv curl -s https://raw.githubusercontent.com/secureblue/secureblue/live/files/system/etc/modprobe.d/blacklist.conf | sudo tee /etc/modprobe.d/server-blacklist.conf > /dev/null sudo chmod 644 /etc/modprobe.d/server-blacklist.conf unpriv curl -s https://raw.githubusercontent.com/TommyTran732/Linux-Setup-Scripts/main/etc/sysctl.d/99-server.conf | sudo tee /etc/sysctl.d/99-server.conf > /dev/null sudo chmod 644 /etc/sysctl.d/99-server.conf diff --git a/Ubuntu-24.04-Desktop.sh b/Ubuntu-24.04-Desktop.sh index 7964c10..5702f3d 100644 --- a/Ubuntu-24.04-Desktop.sh +++ b/Ubuntu-24.04-Desktop.sh @@ -60,7 +60,7 @@ if [ "${virtualization}" = 'parallels' ]; then unpriv curl -s https://raw.githubusercontent.com/TommyTran732/Kernel-Module-Blacklist/main/etc/modprobe.d/workstation-blacklist.conf | sudo tee /etc/modprobe.d/workstation-blacklist.conf > /dev/null sudo chmod 644 /etc/modprobe.d/workstation-blacklist.conf else - unpriv curl -s https://raw.githubusercontent.com/secureblue/secureblue/live/files/system/usr/etc/modprobe.d/blacklist.conf | sudo tee /etc/modprobe.d/workstation-blacklist.conf > /dev/null + unpriv curl -s https://raw.githubusercontent.com/secureblue/secureblue/live/files/system/etc/modprobe.d/blacklist.conf | sudo tee /etc/modprobe.d/workstation-blacklist.conf > /dev/null sudo chmod 644 /etc/modprobe.d/workstation-blacklist.conf fi sudo chmod 644 /etc/modprobe.d/workstation-blacklist.conf diff --git a/Ubuntu-24.04-Server.sh b/Ubuntu-24.04-Server.sh index 674bb5f..7b19426 100644 --- a/Ubuntu-24.04-Server.sh +++ b/Ubuntu-24.04-Server.sh @@ -63,7 +63,7 @@ sudo systemctl daemon-reload sudo systemctl restart ssh # Security kernel settings -unpriv curl -s https://raw.githubusercontent.com/secureblue/secureblue/live/files/system/usr/etc/modprobe.d/blacklist.conf | sudo tee /etc/modprobe.d/server-blacklist.conf > /dev/null +unpriv curl -s https://raw.githubusercontent.com/secureblue/secureblue/live/files/system/etc/modprobe.d/blacklist.conf | sudo tee /etc/modprobe.d/server-blacklist.conf > /dev/null sudo chmod 644 /etc/modprobe.d/server-blacklist.conf unpriv curl -s https://raw.githubusercontent.com/TommyTran732/Linux-Setup-Scripts/main/etc/sysctl.d/99-server.conf | sudo tee /etc/sysctl.d/99-server.conf > /dev/null sudo chmod 644 /etc/sysctl.d/99-server.conf