mirror of
https://github.com/k4yt3x/sysctl.git
synced 2025-12-23 12:46:33 +00:00
Merge pull request #5 from HorlogeSkynet/master
added recommendations from ANSSI
This commit is contained in:
commit
50d77687e4
@ -63,6 +63,11 @@ kernel.pid_max = 4194304
|
|||||||
# reboot machine after kernel panic
|
# reboot machine after kernel panic
|
||||||
#kernel.panic = 10
|
#kernel.panic = 10
|
||||||
|
|
||||||
|
# restrict perf subsystem usage
|
||||||
|
kernel.perf_event_paranoid = 2
|
||||||
|
kernel.perf_cpu_time_max_percent = 1
|
||||||
|
kernel.perf_event_max_sample_rate = 1
|
||||||
|
|
||||||
########## File System ##########
|
########## File System ##########
|
||||||
|
|
||||||
# disallow core dumping by SUID/SGID programs
|
# disallow core dumping by SUID/SGID programs
|
||||||
@ -101,6 +106,9 @@ fs.inotify.max_user_watches = 524288
|
|||||||
|
|
||||||
########## Virtualization ##########
|
########## Virtualization ##########
|
||||||
|
|
||||||
|
# do not allow mmap in lower addresses
|
||||||
|
vm.mmap_min_addr = 65536
|
||||||
|
|
||||||
# improve mmap ASLR effectness
|
# improve mmap ASLR effectness
|
||||||
vm.mmap_rnd_bits=32
|
vm.mmap_rnd_bits=32
|
||||||
vm.mmap_rnd_compat_bits=16
|
vm.mmap_rnd_compat_bits=16
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user