blob: c246ad20920510197527a6cd9d59f6b69146a5d4 [file] [log] [blame]
Dmitry Teselkinee7b8112018-08-22 12:46:08 +03001# 1.1.1.4 Ensure mounting of hfs filesystems is disabled
2#
3# Description
4# ===========
5# The hfs filesystem type is a hierarchical filesystem that allows
6# you to mount Mac OS filesystems.
7#
8# Rationale
9# =========
10# Removing support for unneeded filesystem types reduces the local attack
11# surface of the system. If this filesystem type is not needed, disable it.
12#
13# Audit
14# =====
15# Run the following commands and verify the output is as indicated:
16#
17# # modprobe -n -v hfs
18# install /bin/true
19# # lsmod | grep hfs
20# <No output>
21#
22# Remediation
23# ===========
24# Edit or create the file /etc/modprobe.d/CIS.conf and add the following line:
25#
26# install hfs /bin/true
27#
28parameters:
29 linux:
30 system:
31 kernel:
32 module:
33 hfs:
34 install:
35 command: /bin/true
36