mirror of
https://github.com/anotherhadi/nixy.git
synced 2026-08-22 19:15:48 +02:00
Hardening: Vulnix + kernel hardening
Signed-off-by: Hadi <hadi@example.fr>
This commit is contained in:
@@ -14,6 +14,7 @@
|
|||||||
../../nixos/utils.nix
|
../../nixos/utils.nix
|
||||||
../../nixos/hyprland.nix
|
../../nixos/hyprland.nix
|
||||||
../../nixos/steam.nix
|
../../nixos/steam.nix
|
||||||
|
../../nixos/kernel-hardening.nix
|
||||||
../../home/programs/gui/helium/system.nix # I hate browser's configuration..
|
../../home/programs/gui/helium/system.nix # I hate browser's configuration..
|
||||||
|
|
||||||
# CHANGEME: You should probably remove those things:
|
# CHANGEME: You should probably remove those things:
|
||||||
|
|||||||
@@ -13,6 +13,7 @@
|
|||||||
"/var/lib/systemd/timers" # last-run timestamps (e.g. nix gc weekly)
|
"/var/lib/systemd/timers" # last-run timestamps (e.g. nix gc weekly)
|
||||||
"/var/log"
|
"/var/log"
|
||||||
"/var/cache/tuigreet"
|
"/var/cache/tuigreet"
|
||||||
|
"/var/cache/vulnix"
|
||||||
"/var/db/sudo/lectured" # remembers that the sudo lecture was already shown
|
"/var/db/sudo/lectured" # remembers that the sudo lecture was already shown
|
||||||
];
|
];
|
||||||
|
|
||||||
|
|||||||
@@ -19,7 +19,7 @@
|
|||||||
../../server-modules/bentopdf.nix
|
../../server-modules/bentopdf.nix
|
||||||
../../server-modules/cyberchef.nix
|
../../server-modules/cyberchef.nix
|
||||||
../../server-modules/mazanoke.nix
|
../../server-modules/mazanoke.nix
|
||||||
../../server-modules/kernel-hardening.nix
|
../../nixos/kernel-hardening.nix
|
||||||
../../server-modules/fail2ban.nix
|
../../server-modules/fail2ban.nix
|
||||||
../../server-modules/default-creds.nix
|
../../server-modules/default-creds.nix
|
||||||
../../server-modules/gitea.nix
|
../../server-modules/gitea.nix
|
||||||
|
|||||||
@@ -11,6 +11,8 @@
|
|||||||
../../nixos/users.nix
|
../../nixos/users.nix
|
||||||
../../nixos/utils.nix
|
../../nixos/utils.nix
|
||||||
../../nixos/hyprland.nix
|
../../nixos/hyprland.nix
|
||||||
|
../../nixos/kernel-hardening.nix
|
||||||
|
../../nixos/vulnix.nix
|
||||||
../../home/programs/gui/helium/system.nix # I hate browser's configuration..
|
../../home/programs/gui/helium/system.nix # I hate browser's configuration..
|
||||||
|
|
||||||
# CHANGEME: You should probably remove those things:
|
# CHANGEME: You should probably remove those things:
|
||||||
|
|||||||
@@ -13,6 +13,7 @@
|
|||||||
"/var/lib/systemd/timers" # last-run timestamps (e.g. nix gc weekly)
|
"/var/lib/systemd/timers" # last-run timestamps (e.g. nix gc weekly)
|
||||||
"/var/log"
|
"/var/log"
|
||||||
"/var/cache/tuigreet"
|
"/var/cache/tuigreet"
|
||||||
|
"/var/cache/vulnix"
|
||||||
"/var/db/sudo/lectured" # remembers that the sudo lecture was already shown
|
"/var/db/sudo/lectured" # remembers that the sudo lecture was already shown
|
||||||
];
|
];
|
||||||
|
|
||||||
|
|||||||
@@ -1,4 +1,3 @@
|
|||||||
# Kernel hardening for the server
|
|
||||||
{
|
{
|
||||||
boot.kernel.sysctl = {
|
boot.kernel.sysctl = {
|
||||||
# Restrict access to kernel logs and pointers
|
# Restrict access to kernel logs and pointers
|
||||||
@@ -9,6 +8,18 @@
|
|||||||
"net.core.bpf_jit_harden" = 2;
|
"net.core.bpf_jit_harden" = 2;
|
||||||
"kernel.unprivileged_bpf_disabled" = 1;
|
"kernel.unprivileged_bpf_disabled" = 1;
|
||||||
|
|
||||||
|
# Restrict ptrace to parent processes only
|
||||||
|
"kernel.yama.ptrace_scope" = 1;
|
||||||
|
|
||||||
|
# Disable kexec (loading a new kernel at runtime)
|
||||||
|
"kernel.kexec_load_disabled" = 1;
|
||||||
|
|
||||||
|
# Disable magic SysRq key
|
||||||
|
"kernel.sysrq" = 0;
|
||||||
|
|
||||||
|
# Restrict access to /proc for non-root users
|
||||||
|
"kernel.perf_event_paranoid" = 3;
|
||||||
|
|
||||||
# Reverse path filtering (anti-spoofing)
|
# Reverse path filtering (anti-spoofing)
|
||||||
"net.ipv4.conf.all.rp_filter" = 1;
|
"net.ipv4.conf.all.rp_filter" = 1;
|
||||||
"net.ipv4.conf.default.rp_filter" = 1;
|
"net.ipv4.conf.default.rp_filter" = 1;
|
||||||
@@ -29,7 +40,18 @@
|
|||||||
# Don't send ICMP redirects
|
# Don't send ICMP redirects
|
||||||
"net.ipv4.conf.all.send_redirects" = 0;
|
"net.ipv4.conf.all.send_redirects" = 0;
|
||||||
|
|
||||||
# Restrict ptrace to parent processes only
|
# Ignore bogus ICMP error responses
|
||||||
"kernel.yama.ptrace_scope" = 1;
|
"net.ipv4.icmp_ignore_bogus_error_responses" = 1;
|
||||||
|
|
||||||
|
# Protect against time-wait assassination
|
||||||
|
"net.ipv4.tcp_rfc1337" = 1;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
boot.kernelParams = [
|
||||||
|
"init_on_alloc=1" # zero freshly allocated kernel memory
|
||||||
|
"init_on_free=1" # zero freed kernel memory
|
||||||
|
"slab_nomerge" # don't merge slab caches of different sizes (harder heap grooming)
|
||||||
|
"page_alloc.shuffle=1" # randomize page allocator freelists
|
||||||
|
"randomize_kstack_offset=1" # randomize the kernel stack offset on syscall entry
|
||||||
|
];
|
||||||
}
|
}
|
||||||
@@ -0,0 +1,27 @@
|
|||||||
|
# Vulnix scans the Nix store against the NVD CVE feed to find packages with
|
||||||
|
# known vulnerabilities.
|
||||||
|
{pkgs, ...}: {
|
||||||
|
environment.systemPackages = [pkgs.vulnix];
|
||||||
|
|
||||||
|
systemd.services.vulnix-scan = {
|
||||||
|
description = "Scan the system closure for known vulnerabilities (vulnix)";
|
||||||
|
serviceConfig = {
|
||||||
|
Type = "oneshot";
|
||||||
|
ExecStart = "${pkgs.vulnix}/bin/vulnix --system --cache-dir /var/cache/vulnix";
|
||||||
|
CacheDirectory = "vulnix";
|
||||||
|
# vulnix exits non-zero when it finds vulnerabilities; that's expected,
|
||||||
|
# don't let systemd treat the scan itself as a failure.
|
||||||
|
SuccessExitStatus = "1 2";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
systemd.timers.vulnix-scan = {
|
||||||
|
description = "Daily vulnix scan";
|
||||||
|
wantedBy = ["timers.target"];
|
||||||
|
timerConfig = {
|
||||||
|
OnCalendar = "daily";
|
||||||
|
Persistent = true;
|
||||||
|
RandomizedDelaySec = "1h";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user