diff options
| -rwxr-xr-x | etc.bash | 1 | ||||
| -rw-r--r-- | etc/sysctl.d/99-security.conf | 3 | ||||
| -rw-r--r-- | etc/systemd/coredump.conf | 30 |
3 files changed, 34 insertions, 0 deletions
@@ -7,6 +7,7 @@ sudo cp -v etc/pam.d/system-local-login /etc/pam.d/ sudo cp -v etc/pam.d/system-login /etc/pam.d/ sudo cp -v etc/login.defs /etc/ sudo cp -v etc/updatedb.conf /etc/ +sudo cp -v etc/systemd/coredump.conf /etc/systemd/ sudo cp -v etc/sysctl.d/99-security.conf /etc/sysctl.d/ sudo sysctl --system diff --git a/etc/sysctl.d/99-security.conf b/etc/sysctl.d/99-security.conf index a476e40..d2b9b1b 100644 --- a/etc/sysctl.d/99-security.conf +++ b/etc/sysctl.d/99-security.conf @@ -29,3 +29,6 @@ net.ipv6.conf.all.accept_redirects = 0 net.ipv6.conf.default.accept_redirects = 0 net.ipv4.conf.all.send_redirects = 0 net.ipv4.conf.default.send_redirects = 0 + +# Prevent setuid binaries or privileged processes from dumping core +fs.suid_dumpable = 0 diff --git a/etc/systemd/coredump.conf b/etc/systemd/coredump.conf new file mode 100644 index 0000000..7ec87e1 --- /dev/null +++ b/etc/systemd/coredump.conf @@ -0,0 +1,30 @@ +# This file is part of systemd. +# +# systemd is free software; you can redistribute it and/or modify it under the +# terms of the GNU Lesser General Public License as published by the Free +# Software Foundation; either version 2.1 of the License, or (at your option) +# any later version. +# +# Entries in this file show the compile time defaults. Local configuration +# should be created by either modifying this file (or a copy of it placed in +# /etc/ if the original file is shipped in /usr/), or by creating "drop-ins" in +# the /etc/systemd/coredump.conf.d/ directory. The latter is generally +# recommended. Defaults can be restored by simply deleting the main +# configuration file and all drop-ins located in /etc/. +# +# Use 'systemd-analyze cat-config systemd/coredump.conf' to display the full config. +# +# See coredump.conf(5) for details. + +[Coredump] +Storage=none +ProcessSizeMax=0 +#Storage=external +#Compress=yes +# On 32-bit, the default is 1G instead of 32G. +#ProcessSizeMax=32G +#ExternalSizeMax=32G +#JournalSizeMax=767M +#MaxUse= +#KeepFree= +#EnterNamespace=no |
