Skip to content
Projects
Groups
Snippets
Help
This project
Loading...
Sign in / Register
Toggle navigation
K
kernel-hardening-checker
Overview
Overview
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
fact-depend
kernel-hardening-checker
Commits
d4063eee
Commit
d4063eee
authored
Jul 03, 2020
by
Alexander Popov
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Add the link to huldufolk project by @tych0
parent
1991da2e
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
15 additions
and
0 deletions
+15
-0
README.md
README.md
+15
-0
No files found.
README.md
View file @
d4063eee
...
@@ -254,6 +254,17 @@ __Q:__ What about performance impact of these kernel hardening options?
...
@@ -254,6 +254,17 @@ __Q:__ What about performance impact of these kernel hardening options?
__A:__
Ike Devolder
[
@BlackIkeEagle
][
7
]
made some performance tests and described the results in
[
this article
][
8
]
.
__A:__
Ike Devolder
[
@BlackIkeEagle
][
7
]
made some performance tests and described the results in
[
this article
][
8
]
.
<br
/>
__Q:__
Why enabling
`CONFIG_STATIC_USERMODEHELPER`
breaks various things in my GNU/Linux system?
Do I really need that feature?
__A:__
Linux kernel usermode helpers can be used for privilege escalation in kernel exploits
(
[
example 1
][
9
]
,
[
example 2
][
10
]
).
`CONFIG_STATIC_USERMODEHELPER`
prevents that method. But it
requires the corresponding support in the userspace: see the
[
example implementation
][
11
]
by
Tycho Andersen
[
@tych0
][
12
]
.
[
1
]:
http://kernsec.org/wiki/index.php/Kernel_Self_Protection_Project/Recommended_Settings
[
1
]:
http://kernsec.org/wiki/index.php/Kernel_Self_Protection_Project/Recommended_Settings
[
2
]:
https://docs.clip-os.org/clipos/kernel.html#configuration
[
2
]:
https://docs.clip-os.org/clipos/kernel.html#configuration
[
3
]:
https://grsecurity.net/
[
3
]:
https://grsecurity.net/
...
@@ -262,3 +273,7 @@ __A:__ Ike Devolder [@BlackIkeEagle][7] made some performance tests and describe
...
@@ -262,3 +273,7 @@ __A:__ Ike Devolder [@BlackIkeEagle][7] made some performance tests and describe
[
6
]:
https://github.com/a13xp0p0v/kconfig-hardened-check/issues/38
[
6
]:
https://github.com/a13xp0p0v/kconfig-hardened-check/issues/38
[
7
]:
https://github.com/BlackIkeEagle
[
7
]:
https://github.com/BlackIkeEagle
[
8
]:
https://blog.herecura.eu/blog/2020-05-30-kconfig-hardening-tests/
[
8
]:
https://blog.herecura.eu/blog/2020-05-30-kconfig-hardening-tests/
[
9
]:
https://googleprojectzero.blogspot.com/2018/09/a-cache-invalidation-bug-in-linux.html
[
10
]:
https://a13xp0p0v.github.io/2020/02/15/CVE-2019-18683.html
[
11
]:
https://github.com/tych0/huldufolk
[
12
]:
https://github.com/tych0
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment