<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[I&#x27;ve done]]></title><description><![CDATA[<p>I've done</p><p>echo 1 &gt; /proc/sys/kernel/modules_disabled</p><p>on some servers that don't need to load additional modules after startup. I've just configured this to run 5 minutes after boot. (Timing was an arbitrary choice.)</p><p>This reduces the attack surface and should help mitigate against vulnerabilities exploitable via kernel modules that you don't normally use, at the expense of on-demand loading of modules of course (including e.g. usbhid for remote kvm, so make sure whatever you might need is loaded first).</p><p>The setting takes a reboot to undo.</p><p><a href="https://hsnl.social/tags/copyfail" rel="tag">#<span>copyfail</span></a> <a href="https://hsnl.social/tags/dirtyfrag" rel="tag">#<span>dirtyfrag</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/c1f78e70-bc18-42cb-91aa-f2a1821490b2/i-ve-done</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 04:28:38 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/c1f78e70-bc18-42cb-91aa-f2a1821490b2.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 08 May 2026 02:25:07 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to I&#x27;ve done on Fri, 08 May 2026 11:18:03 GMT]]></title><description><![CDATA[<p><span><a href="/user/vive_levant%40masto.bike">@<span>Vive_Levant</span></a></span> </p><p>echo 0 &gt; /proc/sys/kernel/modules_disabled<br />-bash: echo: write error: Invalid argument</p>]]></description><link>https://board.circlewithadot.net/post/https://hsnl.social/users/whreq/statuses/116538676605939780</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hsnl.social/users/whreq/statuses/116538676605939780</guid><dc:creator><![CDATA[whreq@hsnl.social]]></dc:creator><pubDate>Fri, 08 May 2026 11:18:03 GMT</pubDate></item><item><title><![CDATA[Reply to I&#x27;ve done on Fri, 08 May 2026 11:16:25 GMT]]></title><description><![CDATA[<p><span><a href="https://hsnl.social/@whreq">@<span>whreq</span></a></span> you can’t echo 0 in /proc/sys/kernel/modules_disabled to revert ?</p>]]></description><link>https://board.circlewithadot.net/post/https://masto.bike/users/Vive_Levant/statuses/116538670126949917</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://masto.bike/users/Vive_Levant/statuses/116538670126949917</guid><dc:creator><![CDATA[vive_levant@masto.bike]]></dc:creator><pubDate>Fri, 08 May 2026 11:16:25 GMT</pubDate></item></channel></rss>