Skip to content

Commit ceca9ea

Browse files
committed
New hardening configurations
- Disable obscure filesystems - System-wide DoT - and more...
1 parent f3e9562 commit ceca9ea

2 files changed

Lines changed: 144 additions & 29 deletions

File tree

‎README.md‎

Lines changed: 9 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,10 @@ The script uses a standard Whiptail terminal interface. You just check off the f
2222

2323
### Hardening & Privacy
2424
* **Kernel & Network:** Applies Secureblue-inspired sysctl hardening, randomizes MAC addresses, and sets Firewalld to DROP.
25-
* **Hardcore Kernel Hardening Args** Applies "Hardcore" kernel hardening.
25+
* **Hardcore Kernel Hardening Args:** Applies "Hardcore" kernel hardening arguments via GRUB.
26+
* **Strict Flatpak Overrides:** Revokes overly broad filesystem and device permissions globally, and installs Flatseal so you can selectively re-enable access per app.
27+
* **Secure DNS (DoT):** Enables system-wide DNS-over-TLS via `systemd-resolved` with selectable providers (Cloudflare, Quad9, AdGuard, or Custom IPs).
28+
* **Filesystem Security:** Blacklists obscure, historically vulnerable filesystems (`cramfs`, `hfs`, `udf`, etc.) to prevent kernel exploits via malicious media.
2629
* **Physical Security:** Installs and enables `usbguard` and `fail2ban`.
2730
* **Secure Boot:** Creates and enrolls custom Secure Boot keys via `sbctl`.
2831
* **Tor & VPNs:** Easily install the Tor daemon/browser, IVPN, or Mullvad.
@@ -46,27 +49,27 @@ The script uses a standard Whiptail terminal interface. You just check off the f
4649
You can run this script with a single command without downloading it manually:
4750

4851
```bash
49-
sh -c "$(curl -sS https://raw.githubusercontent.com/vil/fqs/master/fqs)"
52+
sh -c "$(curl -sS [https://raw.githubusercontent.com/vil/fqs/master/fqs](https://raw.githubusercontent.com/vil/fqs/master/fqs))"
5053
```
5154

5255
## Installation
5356
If you prefer to clone the repository and review the code locally before running:
5457

5558
Clone the repository:
5659

57-
```Bash
58-
git clone https://github.com/vil/fqs.git && cd fqs
60+
```bash
61+
git clone [https://github.com/vil/fqs.git](https://github.com/vil/fqs.git) && cd fqs
5962
```
6063

6164
Make the script executable:
6265

63-
```Bash
66+
```bash
6467
chmod +x fqs
6568
```
6669

6770
Run the script:
6871

69-
```Bash
72+
```bash
7073
./fqs
7174
```
7275

‎fqs‎

Lines changed: 135 additions & 23 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
# |----------------------------------------------------------|
44
# | Copyright (c) 2024-2026 Vili <https://vili.dev>. GPL-3.0 |
55
# |----------------------------------------------------------|
6-
# Made in Finland.
6+
# Made in Finland.
77

88
set -euo pipefail
99

@@ -80,11 +80,14 @@ EOF
8080
sudo systemctl enable --now dnf-automatic.timer
8181
}
8282

83-
sys_hardening() {
84-
echo -e "\n=> Applying System Hardening..."
83+
install_fail2ban() {
84+
echo -e "\n=> Installing and enabling Fail2Ban..."
8585
sudo dnf install -y fail2ban
8686
sudo systemctl enable --now fail2ban
87+
}
8788

89+
mac_randomization() {
90+
echo -e "\n=> Enabling MAC Randomization..."
8891
local macrandomize_rule="/etc/NetworkManager/conf.d/00-macrandomize.conf"
8992
if [ ! -f "$macrandomize_rule" ]; then
9093
sudo tee -a "$macrandomize_rule" >/dev/null <<'EOF'
@@ -96,18 +99,23 @@ wifi.cloned-mac-address=random
9699
ethernet.cloned-mac-address=random
97100
EOF
98101
fi
102+
sudo systemctl restart NetworkManager
103+
}
99104

105+
ipv6_privacy() {
106+
echo -e "\n=> Enabling IPv6 Privacy Extensions..."
100107
local ipv6_privacy_rule="/etc/NetworkManager/conf.d/00-ipv6-privacy.conf"
101108
if [ ! -f "$ipv6_privacy_rule" ]; then
102109
sudo tee -a "$ipv6_privacy_rule" >/dev/null <<'EOF'
103110
[connection]
104111
ipv6.ip6-privacy=2
105112
EOF
106113
fi
107-
108114
sudo systemctl restart NetworkManager
115+
}
109116

110-
echo "Applying sysctl hardening..."
117+
sysctl_hardening() {
118+
echo -e "\n=> Applying sysctl hardening..."
111119
local sysctl_file="/etc/sysctl.d/55-hardening.conf"
112120
sudo tee "$sysctl_file" >/dev/null <<'EOF'
113121
net.ipv4.tcp_syncookies = 1
@@ -117,17 +125,24 @@ net.ipv4.icmp_ignore_bogus_error_responses = 1
117125
net.ipv4.tcp_timestamps = 0
118126
net.ipv4.conf.all.rp_filter = 1
119127
net.ipv4.conf.default.rp_filter = 1
120-
net.ipv4.conf.*.send_redirects = 0
121-
net.ipv4.conf.*.accept_redirects = 0
122-
net.ipv6.conf.*.accept_redirects = 0
123-
net.ipv4.conf.*.shared_media = 0
124-
net.ipv4.conf.*.arp_filter = 1
125-
net.ipv4.conf.*.arp_ignore = 2
128+
net.ipv4.conf.all.accept_redirects = 0
129+
net.ipv4.conf.default.accept_redirects = 0
130+
net.ipv4.conf.all.secure_redirects = 0
131+
net.ipv4.conf.default.secure_redirects = 0
132+
net.ipv6.conf.all.accept_redirects = 0
133+
net.ipv6.conf.default.accept_redirects = 0
134+
net.ipv4.conf.all.send_redirects = 0
135+
net.ipv4.conf.default.send_redirects = 0
136+
net.ipv4.conf.all.shared_media = 0
137+
net.ipv4.conf.all.arp_filter = 1
138+
net.ipv4.conf.all.arp_ignore = 2
126139
net.ipv4.conf.all.drop_gratuitous_arp = 1
127-
net.ipv4.conf.*.accept_source_route = 0
128-
net.ipv6.conf.*.accept_source_route = 0
129-
net.ipv4.tcp_sack=0
130-
net.ipv4.tcp_dsack=0
140+
net.ipv4.conf.all.accept_source_route = 0
141+
net.ipv4.conf.default.accept_source_route = 0
142+
net.ipv6.conf.all.accept_source_route = 0
143+
net.ipv6.conf.default.accept_source_route = 0
144+
net.ipv4.tcp_sack = 0
145+
net.ipv4.tcp_dsack = 0
131146
net.ipv6.conf.all.use_tempaddr = 2
132147
net.ipv6.conf.default.use_tempaddr = 2
133148
net.ipv4.conf.all.log_martians = 1
@@ -138,9 +153,9 @@ kernel.sysrq = 0
138153
kernel.perf_event_paranoid = 3
139154
kernel.kptr_restrict = 2
140155
kernel.dmesg_restrict = 1
141-
kernel.oops_limit=100
142-
kernel.warn_limit=100
143-
kernel.panic=-1
156+
kernel.oops_limit = 100
157+
kernel.warn_limit = 100
158+
kernel.panic = -1
144159
fs.binfmt_misc.status = 0
145160
fs.suid_dumpable = 0
146161
fs.protected_regular = 2
@@ -160,8 +175,64 @@ vm.mmap_min_addr = 65536
160175
vm.max_map_count = 1048576
161176
EOF
162177
sudo sysctl --system
163-
echo "Disabling cups and avahi-daemon..."
164-
sudo systemctl disable cups avahi-daemon
178+
}
179+
180+
disable_cups_avahi() {
181+
echo -e "\n=> Disabling CUPS and Avahi-daemon..."
182+
sudo systemctl disable --now cups avahi-daemon
183+
}
184+
185+
disable_wifi() {
186+
echo -e "\n=> Completely disabling Wi-Fi capability..."
187+
sudo nmcli radio wifi off || true
188+
sudo rfkill block wifi || true
189+
sudo systemctl disable --now wpa_supplicant
190+
echo "install iwlwifi /bin/true" | sudo tee /etc/modprobe.d/disable-wifi.conf >/dev/null
191+
echo "install iwlmvm /bin/true" | sudo tee -a /etc/modprobe.d/disable-wifi.conf >/dev/null
192+
echo "install rt2800pci /bin/true" | sudo tee -a /etc/modprobe.d/disable-wifi.conf >/dev/null
193+
echo "install ath9k /bin/true" | sudo tee -a /etc/modprobe.d/disable-wifi.conf >/dev/null
194+
}
195+
196+
disable_bluetooth() {
197+
echo -e "\n=> Completely disabling Bluetooth capability..."
198+
sudo systemctl disable --now bluetooth
199+
sudo rfkill block bluetooth || true
200+
echo "install btusb /bin/true" | sudo tee /etc/modprobe.d/disable-bluetooth.conf >/dev/null
201+
echo "install bluetooth /bin/true" | sudo tee -a /etc/modprobe.d/disable-bluetooth.conf >/dev/null
202+
}
203+
204+
disable_webcam() {
205+
echo -e "\n=> Completely disabling Webcam capability..."
206+
echo "install uvcvideo /bin/true" | sudo tee /etc/modprobe.d/disable-webcam.conf >/dev/null
207+
}
208+
209+
disable_obscure_fs() {
210+
echo -e "\n=> Disabling obscure filesystems..."
211+
local fs_list="cramfs freevxfs jffs2 hfs hfsplus squashfs udf"
212+
for fs in $fs_list; do
213+
echo "install $fs /bin/true" | sudo tee -a /etc/modprobe.d/disable-fs.conf >/dev/null
214+
done
215+
}
216+
217+
enable_secure_dns() {
218+
local dns_ips="$1"
219+
echo -e "\n=> Enabling System-wide DNS-over-TLS (DoT) with IPs: $dns_ips"
220+
sudo mkdir -p /etc/systemd/resolved.conf.d
221+
sudo tee /etc/systemd/resolved.conf.d/dns_over_tls.conf >/dev/null <<EOF
222+
[Resolve]
223+
DNS=$dns_ips
224+
DNSOverTLS=yes
225+
EOF
226+
sudo systemctl restart systemd-resolved
227+
}
228+
229+
strict_flatpak_overrides() {
230+
echo -e "\n=> Applying Strict Flatpak Overrides & Installing Flatseal..."
231+
sudo flatpak override --nofilesystem=host
232+
sudo flatpak override --nofilesystem=home
233+
sudo flatpak override --nodevice=all
234+
sudo dnf install flatpak -y >/dev/null
235+
flatpak install -y flathub com.github.tchx84.Flatseal || echo "Warning: Flatseal failed to install."
165236
}
166237

167238
hardcore_kernel_args() {
@@ -326,11 +397,18 @@ whiptail --title "FQS (Fedora Quick Start)" --msgbox "Welcome to the Fedora Quic
326397

327398
# 1. Base Configuration Checklist
328399
BASE_OPTS=$(whiptail --title "System Base Configuration" --checklist \
329-
"Select system tweaks to apply (Space to select, Enter to confirm):" 22 75 12 \
400+
"Select system tweaks to apply (Space to select, Enter to confirm):" 29 80 20 \
330401
"UPDATE" "Perform Full System Upgrade" ON \
331402
"REPOS" "Enable RPM Fusion & Flathub" ON \
332403
"DNF" "Optimize DNF Configuration" ON \
333-
"HARDEN" "Apply System Hardening (Fail2Ban, Sysctl, etc)" ON \
404+
"FAIL2BAN" "Install and enable Fail2Ban" ON \
405+
"MAC_RAND" "Enable MAC Address Randomization" ON \
406+
"IPV6_PRIV" "Enable IPv6 Privacy Extensions" ON \
407+
"SYSCTL" "Apply Sysctl Kernel Hardening" ON \
408+
"FLATPAK_STRICT" "Strict Flatpak Overrides & Install Flatseal" OFF \
409+
"SECURE_DNS" "Enable System-wide DNS-over-TLS (DoT)" OFF \
410+
"DIS_FS" "Disable obscure filesystems (cramfs, hfs, udf, etc.)" OFF \
411+
"DIS_PRINTERS" "Disable CUPS & Avahi (Printers/Discovery)" ON \
334412
"FIREWALL" "Set Firewalld default zone to DROP" ON \
335413
"USBGUARD" "Set up USBGuard to block unauthorized devices" OFF \
336414
"KERNEL" "Apply Hardcore Kernel Hardening" OFF \
@@ -341,9 +419,33 @@ BASE_OPTS=$(whiptail --title "System Base Configuration" --checklist \
341419
"NVIDIA" "Install Nvidia Drivers (akmod-nvidia)" OFF \
342420
"APPLE_KBD" "Patch Apple Keyboard FN key (hid_apple)" OFF \
343421
"DRACUT" "Allow BT keyboard during LUKS decryption" OFF \
422+
"DIS_WIFI" "Completely Disable Wi-Fi (Modprobe & NM)" OFF \
423+
"DIS_BT" "Completely Disable Bluetooth (Modprobe & RFKill)" OFF \
424+
"DIS_WEBCAM" "Completely Disable Webcam (uvcvideo)" OFF \
344425
3>&1 1>&2 2>&3) || exit 0
345426
BASE_OPTS=$(echo "$BASE_OPTS" | tr -d '"')
346427

428+
# 1.5 Secure DNS Provider (If selected)
429+
DNS_IPS=""
430+
if [[ "$BASE_OPTS" == *"SECURE_DNS"* ]]; then
431+
DNS_CHOICE=$(whiptail --title "Secure DNS Provider" --radiolist \
432+
"Choose a DNS-over-TLS provider:" 15 70 4 \
433+
"Cloudflare" "1.1.1.1 (Fast, Privacy-focused)" ON \
434+
"Quad9" "9.9.9.9 (Malware blocking)" OFF \
435+
"AdGuard" "94.140.14.14 (Ad & Tracker blocking)" OFF \
436+
"Custom" "Enter your own IPs (Space separated)" OFF \
437+
3>&1 1>&2 2>&3) || exit 0
438+
439+
case "$DNS_CHOICE" in
440+
"Cloudflare") DNS_IPS="1.1.1.1 1.0.0.1 2606:4700:4700::1111 2606:4700:4700::1001" ;;
441+
"Quad9") DNS_IPS="9.9.9.9 149.112.112.112 2620:fe::fe 2620:fe::9" ;;
442+
"AdGuard") DNS_IPS="94.140.14.14 94.140.15.15 2a10:50c0::ad1:ff 2a10:50c0::ad2:ff" ;;
443+
"Custom")
444+
DNS_IPS=$(whiptail --title "Custom DNS" --inputbox "Enter DNS IPs (IPv4 and/or IPv6, space-separated):" 10 70 3>&1 1>&2 2>&3) || exit 0
445+
;;
446+
esac
447+
fi
448+
347449
# 2. Browser Selection
348450
BROWSER=$(whiptail --title "Web Browser" --radiolist \
349451
"Choose your preferred browser:" 15 60 6 \
@@ -410,7 +512,17 @@ clear
410512
[[ "$BASE_OPTS" == *"UPDATE"* ]] && sys_update
411513
[[ "$BASE_OPTS" == *"REPOS"* ]] && add_rpm_repos
412514
[[ "$BASE_OPTS" == *"AUTO_UPDATES"* ]] && setup_auto_updates
413-
[[ "$BASE_OPTS" == *"HARDEN"* ]] && sys_hardening
515+
[[ "$BASE_OPTS" == *"FAIL2BAN"* ]] && install_fail2ban
516+
[[ "$BASE_OPTS" == *"MAC_RAND"* ]] && mac_randomization
517+
[[ "$BASE_OPTS" == *"IPV6_PRIV"* ]] && ipv6_privacy
518+
[[ "$BASE_OPTS" == *"SYSCTL"* ]] && sysctl_hardening
519+
[[ "$BASE_OPTS" == *"FLATPAK_STRICT"* ]] && strict_flatpak_overrides
520+
[[ "$BASE_OPTS" == *"SECURE_DNS"* ]] && enable_secure_dns "$DNS_IPS"
521+
[[ "$BASE_OPTS" == *"DIS_FS"* ]] && disable_obscure_fs
522+
[[ "$BASE_OPTS" == *"DIS_PRINTERS"* ]] && disable_cups_avahi
523+
[[ "$BASE_OPTS" == *"DIS_WIFI"* ]] && disable_wifi
524+
[[ "$BASE_OPTS" == *"DIS_BT"* ]] && disable_bluetooth
525+
[[ "$BASE_OPTS" == *"DIS_WEBCAM"* ]] && disable_webcam
414526
[[ "$BASE_OPTS" == *"FIREWALL"* ]] && setup_firewall_drop
415527
[[ "$BASE_OPTS" == *"USBGUARD"* ]] && setup_usbguard
416528
[[ "$BASE_OPTS" == *"KERNEL"* ]] && hardcore_kernel_args

0 commit comments

Comments
 (0)