diff options
Diffstat (limited to 'security-blueprint/part-4/3-Consoles.md')
-rw-r--r-- | security-blueprint/part-4/3-Consoles.md | 20 |
1 files changed, 10 insertions, 10 deletions
diff --git a/security-blueprint/part-4/3-Consoles.md b/security-blueprint/part-4/3-Consoles.md index 5cb2298..c6cf80a 100644 --- a/security-blueprint/part-4/3-Consoles.md +++ b/security-blueprint/part-4/3-Consoles.md @@ -4,7 +4,7 @@ The serial console should be disabled to prevent an attacker from accessing this powerful interface. -<!-- config --> +<!-- section-config --> Domain | `Config` name | `Value` ------------------------ | ---------------------------- | ------- @@ -13,7 +13,7 @@ Kernel-Consoles-Serial-2 | `CONFIG_SERIAL_8250_CONSOLE` | `n` Kernel-Consoles-Serial-3 | `CONFIG_SERIAL_CORE` | `n` Kernel-Consoles-Serial-4 | `CONFIG_SERIAL_CORE_CONSOLE` | `n` -<!-- endconfig --> +<!-- end-section-config --> -------------------------------------------------------------------------------- @@ -23,7 +23,7 @@ The kernel command-line is used to control many aspects of the booting kernel, a Set the kernel command line in the `CONFIG_CMDLINE KConfig` item and then pass no arguments from the bootloader. -<!-- config --> +<!-- section-config --> Domain | `Config` name | `Value` ----------------------------- | ------------------------- | ----------------------------------- @@ -31,7 +31,7 @@ Kernel-Consoles-CommandLine-1 | `CONFIG_CMDLINE_BOOL` | `y` Kernel-Consoles-CommandLine-2 | `CONFIG_CMDLINE` | `"insert kernel command line here"` Kernel-Consoles-CommandLine-3 | `CONFIG_CMDLINE_OVERRIDE` | `y` -<!-- endconfig --> +<!-- end-section-config --> It is recommended that any per-device settings (e.g: MAC addresses, serial numbers, etc.) be stored and accessed from read-only memory (or files), and that any such parameters be verified (signature checking) prior to their use. @@ -41,13 +41,13 @@ It is recommended that any per-device settings (e.g: MAC addresses, serial numbe The Linux kernel supports KGDB over USB and console ports. These mechanisms are controlled by the `kgdbdbgp` and `kgdboc` kernel command-line parameters. It is important to ensure that no shipping product contains a kernel with KGDB compiled-in. -<!-- config --> +<!-- section-config --> Domain | `Config` name | `Value` ---------------------- | ------------- | ------- Kernel-Consoles-KDBG-1 | `CONFIG_KGDB` | `n` -<!-- endconfig --> +<!-- end-section-config --> -------------------------------------------------------------------------------- @@ -55,13 +55,13 @@ Kernel-Consoles-KDBG-1 | `CONFIG_KGDB` | `n` On a few architectures, you can access a powerful debugger interface from the keyboard. The same powerful interface can be present on the serial console (responding to serial break) of Linux on other architectures. Disable to avoid potentially exposing this powerful backdoor. -<!-- config --> +<!-- section-config --> Domain | `Config` name | `Value` ----------------------- | -------------------- | ------- Kernel-Consoles-SysRQ-1 | `CONFIG_MAGIC_SYSRQ` | `n` -<!-- endconfig --> +<!-- end-section-config --> -------------------------------------------------------------------------------- @@ -69,10 +69,10 @@ Kernel-Consoles-SysRQ-1 | `CONFIG_MAGIC_SYSRQ` | `n` This will make possible to plug wrapper-driven binary formats into the kernel. It enables support for binary formats other than ELF. Providing the ability to use alternate interpreters would assist an attacker in discovering attack vectors. -<!-- config --> +<!-- section-config --> Domain | `Config` name | `Value` ------------------------------ | -------------------- | ------- Kernel-Consoles-BinaryFormat-1 | `CONFIG_BINFMT_MISC` | `n` -<!-- endconfig --> +<!-- end-section-config --> |