[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y ] [Search | Free Show | Home]

How do you like to secure/harden your sysctl.conf in Linux systems

This is a blue board which means that it's for everybody (Safe For Work content only). If you see any adult content, please report it.

Thread replies: 8
Thread images: 1

File: 1402585676672.jpg (532KB, 1280x1133px) Image search: [Google]
1402585676672.jpg
532KB, 1280x1133px
How do you like to secure/harden your sysctl.conf in Linux systems for desktop use and server use?
>>
>>56596197
Of course this thread is empty because /g/ is a phoneshit/consumer board for niggers and spics
>>
>>56596332
Why don't you share your configuration first? :^)
>>
>>56596332
It was obvious to everyone but you it seems
>>
>>56596342

Mine is just default Debian right now I was hoping to hear from some experienced guys, doing some research on securing sysctl.conf and there's so many mixed messages, many things will break web browsing functionality for a desktop user but are useful for a server.

Right now my modifications are just disabling ipv6, very dangerous IMO to have ipv6 open.

net.ipv6.conf.all.disable_ipv6=1
net.ipv6.conf.default.disable_ipv6=1
>>
Bump...very interested in hearing some real world applied sysctl's with explanations on the reasoning behind directives you used.
>>
>>56596537
I guess the Arch wiki can be a good start.
https://wiki.archlinux.org/index.php/sysctl

You can also do
sysctl -a
to view all possible values. I unfortunately don't think there's any information included anywhere on what the values do so you'll have to use a search engine for that.
>>
>>56596746

Thank you for the link, will check it out now. I'd personally love to see examples of sysctl configs people have in place and why they've set them up that way in those scenarios.

Here's what I was just looking through, a hardened sysctl.conf for a Ubuntu server setup:
https://easyengine.io/tutorials/linux/sysctl-conf/
Thread posts: 8
Thread images: 1


[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y] [Search | Top | Home]

I'm aware that Imgur.com will stop allowing adult images since 15th of May. I'm taking actions to backup as much data as possible.
Read more on this topic here - https://archived.moe/talk/thread/1694/


If you need a post removed click on it's [Report] button and follow the instruction.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com.
If you like this website please support us by donating with Bitcoins at 16mKtbZiwW52BLkibtCr8jUg2KVUMTxVQ5
All trademarks and copyrights on this page are owned by their respective parties.
Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
This is a 4chan archive - all of the content originated from that site.
This means that RandomArchive shows their content, archived.
If you need information for a Poster - contact them.