Skip to content

Comment on Lynis – Security auditing and hardening tool, for Unix-based systemsparent

Comments

Where does it say on that page that the hardening is not making them world-readable?

If a compiler is found, execution should be limited to authorized users only (e.g. root user).

Unless you also mount some partitions noexec, making things not executable is useless. And if you have access to python/perl/ruby, you can construct any binary in memory anyway. And that's assuming someone's targeting some vulnerability chain which uses the compiler which is a stretch anyway.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.