blob: e2580529d1ce3a084ff7464b53d7746cbb497df0 [file] [log] [blame]
Dmitry Teselkinee7b8112018-08-22 12:46:08 +03001# 1.1.1.5 Ensure mounting of hfsplus filesystems is disabled
2#
3# Description
4# ===========
5# The hfsplus filesystem type is a hierarchical filesystem designed to
6# replace hfs that allows you to mount Mac OS filesystems.
7#
8# Rationale
9# =========
10# Removing support for unneeded filesystem types reduces the local attack
11# surface of the system. If this filesystem type is not needed, disable it.
12#
13# Audit
14# =====
15# Run the following commands and verify the output is as indicated:
16#
17# # modprobe -n -v hfsplus
18# install /bin/true
19# # lsmod | grep hfsplus
20# <No output>
21#
22# Remediation
23# ===========
24# Edit or create the file /etc/modprobe.d/CIS.conf and add the following line:
25#
26# install hfsplus /bin/true
27#
28parameters:
29 linux:
30 system:
31 kernel:
32 module:
33 hfsplus:
34 install:
35 command: /bin/true
36