Skip to content
This repository has been archived by the owner on Jan 15, 2024. It is now read-only.

Commit

Permalink
Merge pull request #37 from madaidan/drives
Browse files Browse the repository at this point in the history
Deny write access to hard drives
  • Loading branch information
Patrick Schleizer committed Feb 9, 2020
2 parents 63fdd03 + 46a6e90 commit 8a23d27
Show file tree
Hide file tree
Showing 2 changed files with 5 additions and 1 deletion.
4 changes: 4 additions & 0 deletions etc/apparmor.d/abstractions/dangerous-files
Expand Up @@ -132,3 +132,7 @@
audit deny /var/lib/hardened-kernel/** rw,
audit deny /usr/share/hardened-kernel/ rw,
audit deny /usr/share/hardened-kernel/** rw,

## Deny write access to hard drives. Otherwise, an attacker can write to
## e.g. /dev/sda to bypass restrictions.
audit deny /dev/sd* rw,
2 changes: 1 addition & 1 deletion etc/apparmor.d/abstractions/init-systemd
Expand Up @@ -228,7 +228,7 @@
/dev/kvm rw,
owner /dev/sr0 rwk,
/dev/log rw,
owner /dev/sd* rwmk,
owner /dev/sd* r,
owner /dev/kmsg rw,
owner /dev/fb0 rw,
owner /dev/vga_arbiter rw,
Expand Down

0 comments on commit 8a23d27

Please sign in to comment.