thinrasp/etc_org/sysctl.d/10-link-restrictions.conf
2019-11-26 21:36:24 +01:00

6 lines
257 B
Plaintext

# These settings eliminate an entire class of security vulnerability:
# time-of-check-time-of-use cross-privilege attacks using guessable
# filenames (generally seen as "/tmp file race" vulnerabilities).
fs.protected_hardlinks = 1
fs.protected_symlinks = 1