diff options
author | netblue30 <netblue30@yahoo.com> | 2016-07-03 09:33:17 -0400 |
---|---|---|
committer | netblue30 <netblue30@yahoo.com> | 2016-07-03 09:33:17 -0400 |
commit | 5c85f2e8eef026fe8463500383a0e61f346d610c (patch) | |
tree | 3bfeefcda47d8d97f616dee5b119d0a1403e5cd6 | |
parent | audit: seccomp (diff) | |
download | firejail-5c85f2e8eef026fe8463500383a0e61f346d610c.tar.gz firejail-5c85f2e8eef026fe8463500383a0e61f346d610c.tar.zst firejail-5c85f2e8eef026fe8463500383a0e61f346d610c.zip |
audit: checking files
-rw-r--r-- | src/faudit/files.c | 73 | ||||
-rw-r--r-- | src/faudit/main.c | 3 | ||||
-rw-r--r-- | todo | 16 |
3 files changed, 92 insertions, 0 deletions
diff --git a/src/faudit/files.c b/src/faudit/files.c new file mode 100644 index 000000000..0463af66d --- /dev/null +++ b/src/faudit/files.c | |||
@@ -0,0 +1,73 @@ | |||
1 | /* | ||
2 | * Copyright (C) 2014-2016 Firejail Authors | ||
3 | * | ||
4 | * This file is part of firejail project | ||
5 | * | ||
6 | * This program is free software; you can redistribute it and/or modify | ||
7 | * it under the terms of the GNU General Public License as published by | ||
8 | * the Free Software Foundation; either version 2 of the License, or | ||
9 | * (at your option) any later version. | ||
10 | * | ||
11 | * This program is distributed in the hope that it will be useful, | ||
12 | * but WITHOUT ANY WARRANTY; without even the implied warranty of | ||
13 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | ||
14 | * GNU General Public License for more details. | ||
15 | * | ||
16 | * You should have received a copy of the GNU General Public License along | ||
17 | * with this program; if not, write to the Free Software Foundation, Inc., | ||
18 | * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. | ||
19 | */ | ||
20 | #include "faudit.h" | ||
21 | #include <fcntl.h> | ||
22 | #include <pwd.h> | ||
23 | |||
24 | static char *username = NULL; | ||
25 | static char *homedir = NULL; | ||
26 | |||
27 | static void check_home_file(const char *name) { | ||
28 | assert(homedir); | ||
29 | |||
30 | char *fname; | ||
31 | if (asprintf(&fname, "%s/%s", homedir, name) == -1) | ||
32 | errExit("asprintf"); | ||
33 | |||
34 | if (access(fname, R_OK) == 0) | ||
35 | printf("UGLY: I can access files in %s directory\n", fname); | ||
36 | else | ||
37 | printf("GOOD: I cannot access files in %s directory\n", fname); | ||
38 | |||
39 | free(fname); | ||
40 | } | ||
41 | |||
42 | void files_test(void) { | ||
43 | struct passwd *pw = getpwuid(getuid()); | ||
44 | if (!pw) { | ||
45 | fprintf(stderr, "Error: cannot retrive user account information\n"); | ||
46 | return; | ||
47 | } | ||
48 | |||
49 | username = strdup(pw->pw_name); | ||
50 | if (!username) | ||
51 | errExit("strdup"); | ||
52 | homedir = strdup(pw->pw_dir); | ||
53 | if (!homedir) | ||
54 | errExit("strdup"); | ||
55 | |||
56 | // check access to .ssh directory | ||
57 | check_home_file(".ssh"); | ||
58 | |||
59 | // check access to .gnupg directory | ||
60 | check_home_file(".gnupg"); | ||
61 | |||
62 | // check access to Firefox browser directory | ||
63 | check_home_file(".mozilla"); | ||
64 | |||
65 | // check access to Chromium browser directory | ||
66 | check_home_file(".config/chromium"); | ||
67 | |||
68 | // check access to Debian Icedove directory | ||
69 | check_home_file(".icedove"); | ||
70 | |||
71 | // check access to Thunderbird directory | ||
72 | check_home_file(".thunderbird"); | ||
73 | } | ||
diff --git a/src/faudit/main.c b/src/faudit/main.c index cd358cc1a..2ed3aa2e1 100644 --- a/src/faudit/main.c +++ b/src/faudit/main.c | |||
@@ -53,6 +53,9 @@ int main(int argc, char **argv) { | |||
53 | // check seccomp | 53 | // check seccomp |
54 | seccomp_test(); | 54 | seccomp_test(); |
55 | 55 | ||
56 | // check some well-known problematic files | ||
57 | files_test(); | ||
58 | |||
56 | free(prog); | 59 | free(prog); |
57 | printf("--------------------------------------------------------------------------------\n"); | 60 | printf("--------------------------------------------------------------------------------\n"); |
58 | return 0; | 61 | return 0; |
@@ -123,3 +123,19 @@ GOOD: all capabilities are disabled | |||
123 | 123 | ||
124 | 124 | ||
125 | Parent is shutting down, bye... | 125 | Parent is shutting down, bye... |
126 | |||
127 | 16. Sound devices: | ||
128 | /dev/snd | ||
129 | |||
130 | |||
131 | /dev/snd/pcmC0D0 -> /dev/audio0 (/dev/audio) -> minor 4 | ||
132 | /dev/snd/pcmC0D0 -> /dev/dsp0 (/dev/dsp) -> minor 3 | ||
133 | /dev/snd/pcmC0D1 -> /dev/adsp0 (/dev/adsp) -> minor 12 | ||
134 | /dev/snd/pcmC1D0 -> /dev/audio1 -> minor 4+16 = 20 | ||
135 | /dev/snd/pcmC1D0 -> /dev/dsp1 -> minor 3+16 = 19 | ||
136 | /dev/snd/pcmC1D1 -> /dev/adsp1 -> minor 12+16 = 28 | ||
137 | /dev/snd/pcmC2D0 -> /dev/audio2 -> minor 4+32 = 36 | ||
138 | /dev/snd/pcmC2D0 -> /dev/dsp2 -> minor 3+32 = 35 | ||
139 | /dev/snd/pcmC2D1 -> /dev/adsp2 -> minor 12+32 = 44 | ||
140 | |||
141 | |||